typeentityconfidencehighupdated2026-08-11malware-familyc2defense-evasionsigningremote-access-tool-abuse

ConnectWise (ScreenConnect) abuse

Abuse of the legitimate ConnectWise ScreenConnect remote-access platform via malicious signed binaries (both MSI-bundle self-contained installers and ClickOnce bootstrappers) bearing compromised or fraudulently issued ConnectWise Authenticode certificates.

Overview

ConnectWise ScreenConnect is a legitimate enterprise remote-access and remote-support platform. Attackers have been observed distributing two deployment morphs:

  1. MSI-bundle self-contained installers (Nov 2022 batch) — full ScreenConnect client embedded as .NET assemblies inside a PE32 wrapper, installed via WiX MSI tables. Valid Authenticode by ConnectWise, LLC.
  2. ClickOnce bootstrappers (Apr–May 2025 batch) — minimal C++ runners that install the publisher certificate into TrustedPublisher and invoke dfshim.dll to pull a remote .application manifest.

First observed sample: 7145e8 (Nov 2022 build, full MSI bundle via OpenCTI / abuse.ch). Second observed variant: 81adbf9a (Apr 2025 build, ClickOnce bootstrapper). The attacker evolved from full self-contained installer to minimal network-staged bootstrapper over ~2.5 years.

Third confirmed sibling: b831f47e (Nov 2022 build, same MSI bundle structure as 7145e8, ssdeep similarity 99, differing only by hardcoded C2 IP: 104.236.198.16:8041 versus 134.122.4.2:8041). This confirms the builder was parameterized for C2 endpoints while leaving all other artefacts — build timestamp, PDB path, ProductCode, MSI tables — unchanged.

Tenth confirmed sibling aa116a62 (Aug 2026 analysis of Nov 2022 build) adds a fifth distinct C2 IP (193.26.115.231:8041) and a certificate timestamp (2024-10-28) roughly two years after compilation, suggesting delayed re-signing of stockpiled builds. ^[/intel/analyses/aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60.html]

Eleventh confirmed sibling 0600f397 (Aug 2026 analysis) adds a sixth distinct C2 IP (178.16.55.11:8041) to the Nov 2022 MSI-bundle Variant A cluster. Identical compile timestamp, PDB path, ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D}, and ssdeep similarity 99 to 7145e8. A 2024 DigiCert timestamp counter-signature is present, reinforcing the delayed re-signing hypothesis. ^[/intel/analyses/0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481.html]

Build-stack typically observed

Two deployment morphs observed:

Variant A — MSI bundle (7145e8, Nov 2022):

  • Compiler: MSVC 14.33 (Visual Studio 2019/2022) ^[raw/analyses/7145e8/report.md]
  • Language: C/C++ native wrapper bootstrapping embedded .NET 2.0 assemblies (CIL)
  • Linker flags: /DYNAMICBASE, /NXCOMPAT
  • Signing: Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[raw/analyses/7145e8/report.md]
  • PDB leak: C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb
  • Deployment: Self-contained PE32 with embedded ScreenConnect assemblies in .rsrc, loaded via mscoree!CorBindToRuntimeEx; MSI payload installs services, credential providers, and LSA auth packages.

Variant B — ClickOnce bootstrapper (81adbf9a, Apr 2025):

  • Compiler: MSVC 14.40 (Visual Studio 2022) ^[raw/analyses/81adbf9a/report.md]
  • Language: C/C++ (no .NET runtime)
  • Linker flags: /DYNAMICBASE, /NXCOMPAT, CastGuard enabled
  • Signing: Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[raw/analyses/81adbf9a/report.md]
  • PDB leak: C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb
  • No packing, no obfuscation, no anti-debug. The evasion is entirely in the valid signature and the legitimate tool chain.

Deploy / TTPs typically observed

Technique MITRE ID Evidence
Install root / publisher certificate T1553.004 CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[raw/analyses/81adbf9a/report.md]
Remote access software abuse T1219 Hard-coded ScreenConnect C2 endpoint, embedded client assemblies ^[raw/analyses/7145e8/report.md]
Ingress tool transfer T1105 Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[raw/analyses/7145e8/report.md]
Create or Modify System Process (Windows Service) T1543.003 MSI ServiceInstall table + SafeBoot\Network persistence ^[raw/analyses/7145e8/report.md]
OS Credential Dumping: LSASS Memory T1003.001 LSA Authentication Package registration (ScreenConnect.WindowsAuthenticationPackage.dll) ^[raw/analyses/7145e8/report.md]
Input Capture: Credential API Hooking T1056.001 Windows Credential Provider DLL (ScreenConnect.WindowsCredentialProvider.dll) ^[raw/analyses/7145e8/report.md]
Boot or Logon Autostart Execution T1547.012 Credential provider registration at install time ^[raw/analyses/7145e8/report.md]
Valid Accounts (code-signing abuse) T1078 Authenticode by ConnectWise, LLC ^[raw/analyses/7145e8/report.md]
Application-layer C2 T1071.001 HTTP (delegated to dfshim in Variant B; direct via ScreenConnect client in Variant A) ^[raw/analyses/81adbf9a/report.md]
User execution T1204.002 Malicious .application execution flow (Variant B) ^[raw/analyses/81adbf9a/report.md]

Capabilities

  • authenticode-trust-bootstrap-trustedpublisher
  • clickonce-deployment-dfshim-shopenver applicationw
  • remote-access-software-staging
  • certificate-store-manipulation-crypt32
  • http-c2-clickonce-manifest
  • no-direct-socket-api-delegated-http
  • valid-legitimate-certificate-masquerade
  • msi-bundle-self-extracting-installer
  • dotnet-runtime-corbindtoruntimeex
  • embedded-assembly-rcdata-resource-loading
  • service-install-safeboot-persistence
  • lsa-authentication-package-injection
  • windows-credential-provider-registration
  • hardcoded-c2-appconfig
  • wix-toolset-msi-builder
  • certificate-post-deployment-cleanup-certdelete

Variants / Aliases

  • connectwise (OpenCTI label)
  • ScreenConnect (product name used in C2 URL)
  • ClickOnceRunner (PDB / internal build name)

Notable analyses

  • raw/analyses/7145e829/report.md — Self-contained MSI bundle, full ScreenConnect client installer with embedded .NET assemblies, hardcoded C2 134.122.4.2:8041, LSA authentication package, and credential provider registration. MSVC 14.33, Nov 2022 build.
  • raw/analyses/81adbf9a/report.md — Authenticode-backed ClickOnce runner, static-only deep-dive with YARA + Sigma rules. MSVC 14.40, Apr 2025 build.
  • raw/analyses/b831f47e/report.md — Third confirmed sibling (b831f47e, Nov 2022). Near-identical to 7145e8 (ssdeep 99) with C2 IP swapped to 104.236.198.16:8041. Confirms builder parameterization for C2 endpoints.
  • raw/analyses/9477ccddefa6/report.md — Apr 2025 ClickOnce bootstrapper sibling, identical C2 IP 104.236.198.16:8041 to b831f47e, MSVC 14.40, ClickOnceRunner.pdb. Fourth confirmed sibling.
  • raw/analyses/8c8e60afcf9e/report.md — Fifth confirmed sibling (8c8e60af, Nov 2022). Identical MSI bundle to 7145e8/b831f47e (same ProductCode, same version, same DotNetRunner wrapper). New C2 IP 45.83.31.225:8041. Static-only.
  • /intel/analyses/73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37.html — Sixth confirmed sibling (73a8126b, Nov 2022). Identical build to 7145e8/b831f47e/8c8e60af with C2 IP swapped to 84.54.33.84:8041. Confirms builder parameterization for C2 endpoints. Static-only.
  • /intel/analyses/604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886.html — Seventh confirmed sibling (604e1cc7, Apr 2025). ClickOnce bootstrapper twin of 81adbf9a (same compile timestamp to the second, same PDB, same certificate chain) but with C2 IP 45.83.31.225 and https:// protocol. Notably, this IP was first observed in the Nov 2022 MSI-bundle sibling 8c8e60af — first confirmed cross-variant IP reuse across 2.5 years. Adds CertDeleteCertificateFromStore import suggesting touch-and-go certificate cleanup. Static-only.
  • /intel/analyses/050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12.html — Eighth confirmed sibling (050e5825, May 2025). ClickOnce bootstrapper, new compile timestamp (May 20 2025 19:01:23 UTC), same PDB and import surface as Apr 2025 twins. C2 IP 84.54.33.84 reuses infrastructure from Nov 2022 MSI-bundle sibling 73a8126b. Uses https:// protocol. Certificate signing time is ~13 minutes after compile, confirming automated CI/CD signing pipeline. Static-only.
  • /intel/analyses/2186855f4b59b08be5b16aaf91243cf34d8b9d3b7fe91c4746097e6034d0e70f.html — Ninth confirmed sibling (2186855f, May 2025). ClickOnce bootstrapper, identical compile timestamp to the second as 050e5825 (May 20 2025 19:01:23 UTC), same PDB path, same certificate chain. Adds CertDeleteCertificateFromStore cleanup. The ~14-minute gap between compile and certificate signing time confirms automated CI/CD pipeline. C2 URL embedded in Authenticode SPC_SP_OPUS_INFO attribute, not PE strings. Static-only.
  • /intel/analyses/aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60.html — Tenth confirmed sibling (aa116a62, Nov 2022 build). MSI-bundle Variant A, identical ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D} and compile timestamp to prior Nov 2022 siblings. New C2 IP 193.26.115.231:8041 (fifth distinct IP in cluster). DigiCert timestamp signature dated 2024-10-28, ~2 years post-compilation, suggesting delayed re-signing of stockpiled builds. Valid Authenticode by ConnectWise, LLC. Static-only.
  • /intel/analyses/0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481.html — Eleventh confirmed sibling (0600f397, Nov 2022 build). MSI-bundle Variant A, identical ProductCode and compile timestamp. New C2 IP 178.16.55.11:8041 (sixth distinct IP in cluster). DigiCert timestamp counter-signature dated 2024. ssdeep similarity 99 to 7145e8. Static-only.

Related entities / concepts