A phishing email delivered a link that purported to show an order invoice PDF, but led to a real executable: ScreenConnect.ClientSetup[.]exe. The attachment/link tricked basic security controls, and the attacker used a legitimate remote access tool to facilitate the intrusion. The PE file appeared to be a legitimate ScreenConnect client but was preconfigured to callback to a test account controlled by the attacker.
Analysis reveals the embedded configuration within the PE: Relay host relay.screenconnect[.]com on port 443, instance ID v2e3e2 (ConnectWise-hosted cloud), and an RSA-2048 public key. The Authenticode digest matched the signed digest exactly, and there was no overlay or tampering with the certificate table, indicating the trick did not rely on altering the certificate.
The attacker’s configuration demonstrates how widely trusted remote access tools can be abused; ScreenConnect, along with other common RMM/remote tools (AnyDesk, TeamViewer, LogMeIn, Bomgar, Zoho Assist, etc.), are listed as “gold mines” for attackers. The article notes that this kind of abuse makes the threat vector easy to deploy because such tools are trusted by many users.
In terms of response, the piece highlights that this particular vector would be blocked by modern browsers today when attempting to download an executable, underscoring the importance of blocking auto-downloads and scrutinising unsolicited software delivery. The post also points readers to LOLRMM for a broader overview of similar tools. No CVEs are cited in the article.