Find notable cyber news and cases, enriched with sources, timelines, and signals.

ConnectWise ScreenConnect remote access installation chain

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The payload is paired with a decoy docusign.exe and staged to look like a legitimate diagnostic workflow. Once installed, the remote-management tool connects to activeretirementrelocation[.]com, creating a foothold for data theft, cryptocurrency theft, or additional malware.

Related Happenings

COLDCARD ScreenConnect phishing campaign

Campaign
H score39 First: 05.08.2026 20:49 Last: 05.08.2026 20:49 Sources 1

How related: A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.

About this happening: A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...

Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

Campaign
H score45 First: 27.07.2026 15:37 Last: 27.07.2026 15:37 Sources 1

About this happening: The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

VENOMOUS#HELPER phishing campaign using RMM tools

Campaign
H score42 First: 04.05.2026 21:06 Last: 04.05.2026 21:06 Sources 1

About this happening: An active VENOMOUS#HELPER phishing campaign is using legitimate RMM software to establish persistent remote access to compromised hosts, putting over 80 organization...

Latest development: 05.05.2026 17:00

Securonix found the Venomous#Helper phishing campaign using emails impersonating the US Social Security Administration to send victims to gruta[.]com.mx, which served an SSA-branded harvesting page before redirecting to payload delivery from a separate compromised cPanel account. The campaign pairs a self-hosted SimpleHelp 5.0.1 instance with a ConnectWise ScreenConnect relay, and the downloaded JWrapper-packaged binary was signed by SimpleHelp Ltd with a valid Thawte certificate. In a one-hour observation, Securonix recorded 986 background process-creation events and WMIC execution through a renamed wmic.exe.bak copy to evade EDR rules.

Google Ads tax-search ScreenConnect malvertising campaign

Campaign
H score32 First: 24.03.2026 19:05 Last: 24.03.2026 19:05 Sources 1

About this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...

Timeline

  1. 05.08.2026 20:49 2 articles · 1h ago

    Fake COLDCARD audit emails deliver ConnectWise ScreenConnect

    Initial Disclosure

    Proofpoint says a phishing campaign impersonating COLDCARD uses fake security audit emails and coldcardcompliance.com to lure Windows users into downloading a batch file; the payload stages setup.msi and docusign.exe, then installs ConnectWise ScreenConnect to give the operator remote access to the victim device.

    Show sources