CYBERRAKSHAK LABS Β· RESEARCH #052

🚨 Legitimate RMM Software, Unauthorized Remote Access: Attackers Abuse ScreenConnect in Phishing Campaigns

CyberRakshakLabs analyzes a phishing campaign that abuses a genuine, digitally signed ScreenConnect client configured to an attacker-controlled instance, turning trusted RMM software into a remote-access foothold.

By Vivek Kumar Β· Published 5 October 2026
RESEARCH#052
CATEGORYPhishing / RMM Abuse / Remote Access
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-10-05
Source & social links:
LinkedIn Post β†—WhatsApp β†—YouTube β†—
How CyberRakshakLabs researches threats β†’
What if the file is legitimate β€” but the remote session is not?
This campaign shows how a genuine ScreenConnect client can be delivered through phishing, configured to an attacker-controlled instance, and then used as a remote-access foothold.
1Genuine ScreenConnect client used
443Observed relay connection port
v2e3e2Observed ScreenConnect instance ID
Important: The supplied research describes abuse of legitimate RMM software. A valid ConnectWise signature does not prove that the installation was authorised or that the configured instance belongs to the organisation.
1. Executive Summary

The security problem in this campaign is not necessarily a malicious replacement for ScreenConnect. Attackers can instead abuse the legitimate remote-management product itself: trick the victim into installing a genuine client, configure it to an attacker-controlled instance, and then use the resulting remote session as their foothold.

This creates a trust problem. A valid digital signature can tell defenders that a binary was signed by ConnectWise; it does not prove that the installation was authorized, that the configured instance belongs to the organization, or that the resulting remote session is legitimate.

For normal users, an unexpected remote-support installation should therefore be treated as a security event even when the executable is genuine and digitally signed.

Research posture: The supplied brief identifies a ScreenConnect phishing campaign and technical configuration evidence. Public-source verification from GBHackers and the SANS Internet Storm Center independently describes the same abuse pattern involving a genuine ScreenConnect client configured to an operator-controlled instance.
2. Evidence from the Supplied Screenshot

The supplied screenshot shows a ScreenConnect ClientSetup executable and the embedded configuration used by the client. The observed parameters below are preserved from the supplied research input.

Supplied ScreenConnect ClientSetup configuration screenshot showing the embedded relay and instance configuration.
Figure 1. Evidence supplied with the CyberRakshakLabs research input.
ParameterObserved value
Delivery URLhxxps://thelittlecupandsaucer[.]com[.]au/ScreenConnect.ClientSetup.exe
Relay hostinstance-v2e3e2-relay.screenconnect[.]com
Port443
ScreenConnect instance IDv2e3e2
Signing entityConnectWise, LLC
Certificate authorityDigiCert G4 Code Signing CA
Embedded instance keyRSA-2048 public key; blob SHA-256 begins 16b1cec1 and ends 9b0ead7

These are source-provided indicators. Validate them against the current environment before using them for blocking or other automated response.

3. Reconstructed Attack Chain
Phishing message/link→Misleading download→Genuine ScreenConnect client→Attacker-controlled instance→Remote session→Post-access activity
PhaseActivitySecurity meaning
1Phishing message/linkVictim is socially engineered.
2Fake/misleading downloadUser believes remote-support software is required.
3Genuine ScreenConnect clientTraditional malware signatures may not trigger.
4Attacker-controlled instance/relayLegitimate RMM becomes attacker-controlled access.
5Remote sessionAttacker can interact with the endpoint within granted privileges.
6Post-access activityDiscovery, file access or additional tooling may follow.
4. Why This Bypasses Traditional Thinking
File reputation can be clean because the software is legitimate.
Digital signature validation can succeed.
The process name may look normal to the user and SOC.
Remote-control traffic may resemble legitimate IT administration.

The decisive signal becomes authorization context: who installed it, why, which instance it joined and what happened immediately afterward.

5. User Impact
Interactive remote control can expose the desktop and user activity.
Files may be accessed or transferred depending on session privileges.
Attackers may use the RMM foothold to deploy additional tools.
Credentials or browser-session material may become exposed during follow-on activity.
Victims may ignore the compromise because the installed software appears legitimate.
6. Detection & Hunting
Alert on ScreenConnect installations without an approved IT/ITSM ticket.
Record instance IDs and configuration changes for every approved deployment.
Inspect ScreenConnect configuration files for unexpected instance/relay settings.
Correlate installer execution with the preceding browser, email, chat or download event.
Monitor outbound RMM connections and compare them with approved infrastructure.
Alert when newly installed RMM software is followed by PowerShell, command shell, credential access or bulk file activity.
Track who created/deployed the client and from which endpoint.
Treat unexplained RMM installation as a potential incident.
7. Remediation
Download RMM software only from verified vendor channels.
Verify unexpected support requests through a second trusted channel.
Maintain an approved RMM software and instance inventory.
Require MFA for ScreenConnect administration.
Restrict who can deploy RMM clients.
Investigate unauthorized RMM installations, terminate suspicious sessions, preserve evidence and rotate exposed credentials.

ConnectWise documents two-factor authentication as an additional protection for ScreenConnect administration. The stronger organisational control is still to make software, instance, administrator and session authorisation explicit.

8. MITRE ATT&CK β€” Relevant Mapping
TechniqueApplication
T1566 β€” PhishingReported delivery/social-engineering mechanism.
T1219 β€” Remote Access SoftwareLegitimate ScreenConnect is abused as the access mechanism.
T1204.002 β€” User Execution: Malicious FileVictim is induced to execute/install the client.
T1078 β€” Valid AccountsPotential follow-on technique if valid credentials are abused; not confirmed here.
T1105 β€” Ingress Tool TransferPotential post-access use for additional tooling.
9. CyberRakshakLabs Assessment

The answer is not simply to block ScreenConnect. Organizations that legitimately use RMM tools need them. The stronger control is to distinguish software legitimacy from operational legitimacy: approved software, approved instance, approved administrator, expected session and expected behavior.

This campaign illustrates why security teams should correlate RMM installation with the preceding social-engineering event and the configuration of the client itself. The signature answers β€œwho signed the binary?”; it does not answer β€œwho authorised this session?”

πŸ”΄ A signed remote-access tool can still become an attacker's hands when the user installs or authorizes the wrong instance.
10. Sources & Verification Notes

Supplied research input: The uploaded CyberRakshakLabs brief containing the screenshot and technical parameters.

GBHackers: Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access β†—

SANS Internet Storm Center: ScreenConnect Client (Ab)used by Attackers β†—

The technical values shown in the supplied screenshot should be validated in the relevant environment before blocklisting. This research does not claim that every ScreenConnect installation is malicious.

Recommended CyberRakshakLabs Headline

Signed ScreenConnect, Unsigned Trust: How Phishing Turns Legitimate RMM Into Remote Access

Subtitle: A genuine, digitally signed ScreenConnect client can still become an attacker’s foothold when a user is socially engineered into installing or authorizing the wrong instance.