Skip to content

Executive Summary

A phishing email was received with a request to view an invoice PDF and click a link to an executable file. This link led to a ScreenConnect client setup file. Analysis of the file revealed it was a legitimate ScreenConnect client preconfigured to call back an attacker-operated test account, containing configuration details like relay information and an instance key. The execution mechanism exploited a vector where downloaded executables are sometimes permitted, and suspicious files were identified through analysis. The associated tool, ScreenConnect, is listed among several Remote Monitoring and Management (RMM) tools utilized by attackers, including AnyDesk, TeamViewer, and Bomgar.

Facts Only

* An email was received from contact@mejuri[.]com with the subject "EFT Wire Transfer Paid Invoice Receipt."
* The email requested a click on a link to view order information in a PDF.
* The link pointed to hxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe.
* The executable file was analyzed and determined to be a ScreenConnect client preconfigured to call back an attacker's test account.
* Configuration parameters included the Relay (h) instance-v2e3e2-relay.screenconnect.com, Port (p) 443, Instance ID v2e3e2, and an Instance key.
* The executable was signed by ConnectWise, LLC (DigiCert G4 Code Signing CA1), and the Authenticode digest matched the signed digest.
* The file did not contain overlay or injected data, suggesting no signed-but-tampered configuration trick was used.
* Known RMM tools include ScreenConnect, AnyDesk, TeamViewer, LogMeIn, Bomgar, Zoho Assist, rutserv.exe, NetSupport Manager, and SimpleHelp.

Full Take

The narrative highlights the exploitation of low-complexity social engineering—a simple invoice notification—to deliver highly effective, pre-configured remote access tools used by threat actors. The system's success in bypassing initial controls suggests a reliance on established trust hierarchies regarding specific software vendors (ConnectWise). The ease with which legitimate, signed executables can be weaponized demonstrates that the risk is less about the novelty of the malware and more about the mass deployment of trusted, legitimate remote management utilities by adversaries. The implication is that security defenses must shift focus from blocking suspicious file *types* to rigorously scrutinizing the context and destination of executable downloads, especially when they involve applications widely used in legitimate business operations. The dependency on RMM tools as an attack vector points to a systemic failure where the proliferation of trusted remote access software creates an easily accessible, pre-packaged supply chain for initial compromise.
Bridge Questions:
How does the ubiquity of legitimately signed remote management software influence defensive strategies against credential harvesting or session hijacking? What mechanisms exist to differentiate between legitimate configuration files and malicious payloads within these established application frameworks? If attackers rely on abuse of existing applications, what new systemic controls can be implemented beyond traditional signature-based detection to address supply chain risks involving trusted binaries?

From the original · SANS Internet Storm Center

ScreenConnect Client (Ab)used by Attackers Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
Read the full story at isc.sans.edu

Sentinel — Human

Confidence

The content appears to be a firsthand account or detailed analysis shared by an experienced individual dissecting a specific cyber incident and related tooling, making it highly likely human-written.

Signals Detected
low severity: Variable sentence length and direct, observational tone mixed with technical detail.
low severity: The text flows logically from a specific example (phishing) to forensic analysis (PE file inspection) to broader context (RMM tools).
low severity: Proper citation of external sources ([1], [2]) and structured presentation of technical data.
low severity: Specific, verifiable details (e.g., the exact phishing text, the link structure, the PE file configuration table) suggest direct observation rather than pure generation.
Human Indicators
The use of specific, context-heavy examples anchors the narrative in a tangible incident.
The voice exhibits an investigative, operational style typical of security analysts sharing findings.
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st) | Huntaegis