ConnectWise (ScreenConnect) abuse
Abuse of the legitimate ConnectWise ScreenConnect remote-access platform via malicious signed binaries (both MSI-bundle self-contained installers and ClickOnce bootstrappers) bearing compromised or fraudulently issued ConnectWise Authenticode certificates.
Overview
ConnectWise ScreenConnect is a legitimate enterprise remote-access and remote-support platform. Attackers have been observed distributing two deployment morphs:
- MSI-bundle self-contained installers (Nov 2022 batch) — full ScreenConnect client embedded as .NET assemblies inside a PE32 wrapper, installed via WiX MSI tables. Valid Authenticode by ConnectWise, LLC.
- ClickOnce bootstrappers (Apr–May 2025 batch) — minimal C++ runners that install the publisher certificate into
TrustedPublisherand invokedfshim.dllto pull a remote.applicationmanifest.
First observed sample: 7145e8 (Nov 2022 build, full MSI bundle via OpenCTI / abuse.ch). Second observed variant: 81adbf9a (Apr 2025 build, ClickOnce bootstrapper). The attacker evolved from full self-contained installer to minimal network-staged bootstrapper over ~2.5 years.
Third confirmed sibling: b831f47e (Nov 2022 build, same MSI bundle structure as 7145e8, ssdeep similarity 99, differing only by hardcoded C2 IP: 104.236.198.16:8041 versus 134.122.4.2:8041). This confirms the builder was parameterized for C2 endpoints while leaving all other artefacts — build timestamp, PDB path, ProductCode, MSI tables — unchanged.
Tenth confirmed sibling aa116a62 (Aug 2026 analysis of Nov 2022 build) adds a fifth distinct C2 IP (193.26.115.231:8041) and a certificate timestamp (2024-10-28) roughly two years after compilation, suggesting delayed re-signing of stockpiled builds. ^[/intel/analyses/aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60.html]
Eleventh confirmed sibling 0600f397 (Aug 2026 analysis) adds a sixth distinct C2 IP (178.16.55.11:8041) to the Nov 2022 MSI-bundle Variant A cluster. Identical compile timestamp, PDB path, ProductCode {B292C5EA-BF5F-4280-B056-1670FB10BB1D}, and ssdeep similarity 99 to 7145e8. A 2024 DigiCert timestamp counter-signature is present, reinforcing the delayed re-signing hypothesis. ^[/intel/analyses/0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481.html]
Build-stack typically observed
Two deployment morphs observed:
Variant A — MSI bundle (7145e8, Nov 2022):
- Compiler: MSVC 14.33 (Visual Studio 2019/2022) ^[raw/analyses/7145e8/report.md]
- Language: C/C++ native wrapper bootstrapping embedded .NET 2.0 assemblies (CIL)
- Linker flags:
/DYNAMICBASE,/NXCOMPAT - Signing: Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[raw/analyses/7145e8/report.md]
- PDB leak:
C:\Users\jmorgan\Source\cwcontrol\Custom\DotNetRunner\Release\DotNetRunner.pdb - Deployment: Self-contained PE32 with embedded ScreenConnect assemblies in
.rsrc, loaded viamscoree!CorBindToRuntimeEx; MSI payload installs services, credential providers, and LSA auth packages.
Variant B — ClickOnce bootstrapper (81adbf9a, Apr 2025):
- Compiler: MSVC 14.40 (Visual Studio 2022) ^[raw/analyses/81adbf9a/report.md]
- Language: C/C++ (no .NET runtime)
- Linker flags:
/DYNAMICBASE,/NXCOMPAT, CastGuard enabled - Signing: Valid Authenticode by ConnectWise, LLC (DigiCert chain) ^[raw/analyses/81adbf9a/report.md]
- PDB leak:
C:\builds\cc\cwcontrol\Product\ClickOnceRunner\Release\ClickOnceRunner.pdb - No packing, no obfuscation, no anti-debug. The evasion is entirely in the valid signature and the legitimate tool chain.
Deploy / TTPs typically observed
| Technique | MITRE ID | Evidence | |
|---|---|---|---|
| Install root / publisher certificate | T1553.004 | CertOpenSystemStoreA("TrustedPublisher"), CertAddCertificateContextToStore ^[raw/analyses/81adbf9a/report.md] |
|
| Remote access software abuse | T1219 | Hard-coded ScreenConnect C2 endpoint, embedded client assemblies ^[raw/analyses/7145e8/report.md] | |
| Ingress tool transfer | T1105 | Embedded MSI with Cabinet archives installing ScreenConnect from .rsrc ^[raw/analyses/7145e8/report.md] |
|
| Create or Modify System Process (Windows Service) | T1543.003 | MSI ServiceInstall table + SafeBoot\Network persistence ^[raw/analyses/7145e8/report.md] |
|
| OS Credential Dumping: LSASS Memory | T1003.001 | LSA Authentication Package registration (ScreenConnect.WindowsAuthenticationPackage.dll) ^[raw/analyses/7145e8/report.md] |
|
| Input Capture: Credential API Hooking | T1056.001 | Windows Credential Provider DLL (ScreenConnect.WindowsCredentialProvider.dll) ^[raw/analyses/7145e8/report.md] |
|
| Boot or Logon Autostart Execution | T1547.012 | Credential provider registration at install time ^[raw/analyses/7145e8/report.md] | |
| Valid Accounts (code-signing abuse) | T1078 | Authenticode by ConnectWise, LLC ^[raw/analyses/7145e8/report.md] | |
| Application-layer C2 | T1071.001 | HTTP (delegated to dfshim in Variant B; direct via ScreenConnect client in Variant A) ^[raw/analyses/81adbf9a/report.md] | |
| User execution | T1204.002 | Malicious .application execution flow (Variant B) ^[raw/analyses/81adbf9a/report.md] |
Capabilities
authenticode-trust-bootstrap-trustedpublisherclickonce-deployment-dfshim-shopenver applicationwremote-access-software-stagingcertificate-store-manipulation-crypt32http-c2-clickonce-manifestno-direct-socket-api-delegated-httpvalid-legitimate-certificate-masquerademsi-bundle-self-extracting-installerdotnet-runtime-corbindtoruntimeexembedded-assembly-rcdata-resource-loadingservice-install-safeboot-persistencelsa-authentication-package-injectionwindows-credential-provider-registrationhardcoded-c2-appconfigwix-toolset-msi-buildercertificate-post-deployment-cleanup-certdelete
Variants / Aliases
connectwise(OpenCTI label)ScreenConnect(product name used in C2 URL)ClickOnceRunner(PDB / internal build name)
Notable analyses
raw/analyses/7145e829/report.md— Self-contained MSI bundle, full ScreenConnect client installer with embedded .NET assemblies, hardcoded C2134.122.4.2:8041, LSA authentication package, and credential provider registration. MSVC 14.33, Nov 2022 build.raw/analyses/81adbf9a/report.md— Authenticode-backed ClickOnce runner, static-only deep-dive with YARA + Sigma rules. MSVC 14.40, Apr 2025 build.raw/analyses/b831f47e/report.md— Third confirmed sibling (b831f47e, Nov 2022). Near-identical to7145e8(ssdeep 99) with C2 IP swapped to104.236.198.16:8041. Confirms builder parameterization for C2 endpoints.raw/analyses/9477ccddefa6/report.md— Apr 2025 ClickOnce bootstrapper sibling, identical C2 IP104.236.198.16:8041tob831f47e, MSVC 14.40,ClickOnceRunner.pdb. Fourth confirmed sibling.raw/analyses/8c8e60afcf9e/report.md— Fifth confirmed sibling (8c8e60af, Nov 2022). Identical MSI bundle to7145e8/b831f47e(same ProductCode, same version, sameDotNetRunnerwrapper). New C2 IP45.83.31.225:8041. Static-only./intel/analyses/73a8126b8d5443295250815df160f550effeedf1f8adfd0ac2d5160824ca8f37.html— Sixth confirmed sibling (73a8126b, Nov 2022). Identical build to7145e8/b831f47e/8c8e60afwith C2 IP swapped to84.54.33.84:8041. Confirms builder parameterization for C2 endpoints. Static-only./intel/analyses/604e1cc7d2a390a2d211239f4335cb0c0d80d8b9ee48c35f823a78d60e861886.html— Seventh confirmed sibling (604e1cc7, Apr 2025). ClickOnce bootstrapper twin of81adbf9a(same compile timestamp to the second, same PDB, same certificate chain) but with C2 IP45.83.31.225andhttps://protocol. Notably, this IP was first observed in the Nov 2022 MSI-bundle sibling8c8e60af— first confirmed cross-variant IP reuse across 2.5 years. AddsCertDeleteCertificateFromStoreimport suggesting touch-and-go certificate cleanup. Static-only./intel/analyses/050e582512aac223eecc32d19baf386c61353c826404dc4234dfeacd24c0ff12.html— Eighth confirmed sibling (050e5825, May 2025). ClickOnce bootstrapper, new compile timestamp (May 20 2025 19:01:23 UTC), same PDB and import surface as Apr 2025 twins. C2 IP84.54.33.84reuses infrastructure from Nov 2022 MSI-bundle sibling73a8126b. Useshttps://protocol. Certificate signing time is ~13 minutes after compile, confirming automated CI/CD signing pipeline. Static-only./intel/analyses/2186855f4b59b08be5b16aaf91243cf34d8b9d3b7fe91c4746097e6034d0e70f.html— Ninth confirmed sibling (2186855f, May 2025). ClickOnce bootstrapper, identical compile timestamp to the second as050e5825(May 20 2025 19:01:23 UTC), same PDB path, same certificate chain. AddsCertDeleteCertificateFromStorecleanup. The ~14-minute gap between compile and certificate signing time confirms automated CI/CD pipeline. C2 URL embedded in AuthenticodeSPC_SP_OPUS_INFOattribute, not PE strings. Static-only./intel/analyses/aa116a6279aebc383ed7a9321d580f998436e34f06d07f2cb8ac2d7fd876ba60.html— Tenth confirmed sibling (aa116a62, Nov 2022 build). MSI-bundle Variant A, identical ProductCode{B292C5EA-BF5F-4280-B056-1670FB10BB1D}and compile timestamp to prior Nov 2022 siblings. New C2 IP193.26.115.231:8041(fifth distinct IP in cluster). DigiCert timestamp signature dated 2024-10-28, ~2 years post-compilation, suggesting delayed re-signing of stockpiled builds. Valid Authenticode by ConnectWise, LLC. Static-only./intel/analyses/0600f397e12f8eee94623728448eb6a39d3720ca9fed34499715caed8a42f481.html— Eleventh confirmed sibling (0600f397, Nov 2022 build). MSI-bundle Variant A, identical ProductCode and compile timestamp. New C2 IP178.16.55.11:8041(sixth distinct IP in cluster). DigiCert timestamp counter-signature dated 2024. ssdeep similarity 99 to7145e8. Static-only.
Related entities / concepts
- clickonce-certificate-trust-bootstrap — Specific technique page for the certificate → ClickOnce deployment chain
- legitimate-remote-access-tool-abuse — Cross-family concept page covering abuse of legitimate remote-access tools
- netsupport-inno-dropper — Another legitimate remote-access tool (NetSupport Manager) abused via installer repackaging