ConnectWise ScreenConnect remote access installation chain
Malware Activity
Summary
Hide ▲
Show ▼
A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The payload is paired with a decoy docusign.exe and staged to look like a legitimate diagnostic workflow. Once installed, the remote-management tool connects to activeretirementrelocation[.]com, creating a foothold for data theft, cryptocurrency theft, or additional malware.
Related Happenings
COLDCARD ScreenConnect phishing campaign
Campaign
H score39
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
How related:
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
About this happening:
A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
COLDCARD ScreenConnect phishing campaign
CampaignHow related: A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
About this happening: A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
Campaign
H score45
First: 27.07.2026 15:37
Last: 27.07.2026 15:37
Sources 1
About this happening:
The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...
Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect
CampaignAbout this happening: The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
VENOMOUS#HELPER phishing campaign using RMM tools
Campaign
H score42
First: 04.05.2026 21:06
Last: 04.05.2026 21:06
Sources 1
About this happening:
An active VENOMOUS#HELPER phishing campaign is using legitimate RMM software to establish persistent remote access to compromised hosts, putting over 80 organization...
VENOMOUS#HELPER phishing campaign using RMM tools
CampaignAbout this happening: An active VENOMOUS#HELPER phishing campaign is using legitimate RMM software to establish persistent remote access to compromised hosts, putting over 80 organization...
Latest development: 05.05.2026 17:00
Securonix found the Venomous#Helper phishing campaign using emails impersonating the US Social Security Administration to send victims to gruta[.]com.mx, which served an SSA-branded harvesting page before redirecting to payload delivery from a separate compromised cPanel account. The campaign pairs a self-hosted SimpleHelp 5.0.1 instance with a ConnectWise ScreenConnect relay, and the downloaded JWrapper-packaged binary was signed by SimpleHelp Ltd with a valid Thawte certificate. In a one-hour observation, Securonix recorded 986 background process-creation events and WMIC execution through a renamed wmic.exe.bak copy to evade EDR rules.
Google Ads tax-search ScreenConnect malvertising campaign
Campaign
H score32
First: 24.03.2026 19:05
Last: 24.03.2026 19:05
Sources 1
About this happening:
A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Google Ads tax-search ScreenConnect malvertising campaign
CampaignAbout this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Timeline
-
05.08.2026 20:49 2 articles · 1h ago
Fake COLDCARD audit emails deliver ConnectWise ScreenConnect
Initial DisclosureProofpoint says a phishing campaign impersonating COLDCARD uses fake security audit emails and coldcardcompliance.com to lure Windows users into downloading a batch file; the payload stages setup.msi and docusign.exe, then installs ConnectWise ScreenConnect to give the operator remote access to the victim device.
Show sources
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49