Attackers Distributed Malicious ScreenConnect Clients

Threat actors are masking remote access tools with legitimate digital signatures to bypass standard security filters.

Updated on Oct. 1, 2026 in Cybersecurity

Bold flat-color editorial illustration depicting a symbolic padlock with an integrated key-like shackle, representing digital security threats.
Attackers are distributing malicious ScreenConnect remote access tools disguised as wire transfer receipts to evade security filters using legitimate digital signatures. AI Illustration. Upload story photo >

Live Poll

Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?

Attackers have launched a phishing campaign that distributes malicious ScreenConnect client installers disguised as wire transfer receipts. This activity, reported on October 1, 2026, uses legitimate software signatures to evade detection.

Why it matters

The campaign highlights the ongoing security challenge of 'living-off-the-land' techniques, where attackers repurpose legitimate remote monitoring tools to maintain unauthorized network access. By using trusted, signed binaries, these actors successfully bypass many standard endpoint security controls.

The malicious executable, ScreenConnect.ClientSetup.exe, carries a legitimate digital signature from ConnectWise, LLC. Initial analysis showed the file bypassed detection on VirusTotal, relying on browser-based warnings as the primary line of defense.

The players

ConnectWise, LLC

A developer of remote monitoring and management software, including the ScreenConnect platform, whose legitimate digital signature was leveraged in this campaign.

The details

The attackers distribute a legitimate, preconfigured remote monitoring and management (RMM) client that connects to an attacker-controlled account upon execution. Because the installer is a signed, authentic application, it circumvents basic reputation-based security filters. Once the client is installed, the attackers gain remote administrative access to the host machine through established management infrastructure.

Timeline

  1. October 1, 2026: The phishing campaign was identified and reported.

The Tech Race

This activity follows a long-standing pattern of threat actors abusing legitimate administrative utilities, a trend documented by the LOLRMM project remote management tool list. It illustrates the ongoing race between security vendors attempting to flag malicious RMM usage and attackers exploiting the trust embedded in signed enterprise software.

Users should treat unexpected wire transfer receipts, especially those featuring amounts like $5,745.65, with extreme skepticism. Regardless of whether a download file appears digitally signed by a known vendor, users must rely on browser and endpoint security alerts to block unauthorized execution.

The takeaway

Security teams must transition from reputation-based blocking to behavioral analysis to detect when legitimate administrative tools are being used by unauthorized actors. Organizations should monitor their environments for unauthorized RMM installations, even if the files carry valid corporate signatures.

Further reading

For more on how legitimate administrative tools are being co-opted, review the latest trends in Cybersecurity.

More information

Review the full catalog of abused administrative tools on the LOLRMM project remote management tool list.

Source note: This article includes information reported by SANS Internet Storm Center.

Live Poll

Do you trust the authenticity of unexpected digital invoices or receipts sent to your email?