Malware & Tooling

ScreenConnect Installer Turned Trust Into Access

SANS ISC's Xavier Mertens found a phishing email that delivered a genuine ScreenConnect.ClientSetup.exe installer and got around basic security checks. The file was signed by ConnectWise and was used to give attackers remote access to the victim host.

The trick was simple: the installer was a real remote-support client, but it was preconfigured to call back to the attacker's ScreenConnect account. That made it look like normal support software while quietly opening a remote session instead of dropping obvious malware.

The lesson sits with any environment that lets users run signed remote-admin tools such as ScreenConnect, AnyDesk, or TeamViewer. In those shops, the trusted-download path itself can become the intrusion path, and reputation checks alone may not tell you whether a signed installer is helping support or handing over control.

1 source · 3h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-01

Every edition of this story: ScreenConnect Installer Turned Trust Into Access