ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing

ScreenConnect Client Abused by Attackers via Mejuri-Themed (TL-2026-2826) is a medium-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects ConnectWise ScreenConnect (abused as legitimate RMM; no vulnerability), maps to 9 MITRE ATT&CK techniques (T1036, T1071.001, T1090), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2826

Threat ID
TL-2026-2826
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
retail, finance, general enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
11

Malware and tooling in ScreenConnect Client Abused by Attackers via Mejuri-Themed

Malware and tooling: ConnectWise - S0591, ScreenConnect, ScreenConnect relay

A phishing email impersonating jewelry brand Mejuri (fake $5,745.65 'EFT Wire Transfer' payment receipt) lures recipients to download ScreenConnect.ClientSetup.exe from a compromised Australian domain. The file is a genuine, validly ConnectWise-signed ScreenConnect client preconfigured to call back to an attacker-operated ConnectWise-hosted instance via a relay on port 443.

How ScreenConnect Client Abused by Attackers via Mejuri-Themed works

On 2026-10-01 SANS ISC handler Xavier Mertens documented a phishing email spoofing the sender contact@mejuri.com with the subject 'EFT Wire Transfer'. The body claims a payment of $5745.65 was received and urges the recipient to view order information; it also lists a phone number (+1(332)638474823), a typical callback-phishing/refund-scam element. The call-to-action points to hxxps://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, a download hosted on a .com.au domain that appears to be a compromised, unrelated website.

The downloaded executable is not tampered malware. It is a legitimate ScreenConnect client installer signed by 'ConnectWise, LLC' (DigiCert G4 Code Signing CA1) whose Authenticode digest matches and which has no overlay. The attacker-specific part is the embedded client configuration, extracted from the PE: relay instance-v2e3e2-relay.screenconnect.com, port 443, instance ID v2e3e2 (ConnectWise-hosted cloud instance), and an RSA-2048 instance key (SHA256 beginning 16b1cec1, ending 9b00ead7; the diary shows a truncated value). Per the analyst, this is a client preconfigured to call back to a (trial/test) account operated by the attacker. At the time of analysis the sample was unknown on VirusTotal.

Abusing a signed, commercially available RMM tool lets the actor skip custom malware: the valid signature and the trusted screenconnect.com relay domain blend into normal enterprise traffic, and once installed the actor has interactive remote control of the endpoint. The source gives no attribution, malware family, CVE, or follow-on activity. The pattern matches earlier RMM-abuse campaigns described by CISA/NSA/MS-ISAC in advisory AA23-025A (ScreenConnect and AnyDesk delivered via phishing for refund scams) and by Abnormal Security in 2025 (ScreenConnect delivered as fake Zoom/Teams installers). Defenders should treat any unsanctioned ScreenConnect client, especially one calling an instance not owned by the organization, as a potential intrusion.

MITRE ATT&CK techniques used in TL-2026-2826

Defense Evasion

T1036 Masquerading; T1684.001 Impersonation

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1219.002 Remote Desktop Software

Execution

T1204.001 Malicious Link; T1204.002 Malicious File

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1584.001 Domains

Affected products and versions in ScreenConnect Client Abused by Attackers via Mejuri-Themed

  • ConnectWise — ScreenConnect (abused as legitimate RMM; no vulnerability)

Remediation for ScreenConnect Client Abused by Attackers via Mejuri-Themed

Immediate actions

  • Block/alert on DNS and TLS connections to instance-v2e3e2-relay.screenconnect.com and any ScreenConnect instance ID not owned by the organization
  • Block thelittlecupandsaucer.com.au and the URL path /ScreenConnect.ClientSetup.exe at web proxy/DNS
  • Search email logs for sender contact@mejuri.com with subject 'EFT Wire Transfer' and purge matching messages
  • Hunt endpoints for ScreenConnect.ClientSetup.exe executions and ScreenConnect client services/ClickOnce artifacts, then isolate and reimage hosts that ran it

Workarounds

  • Where ScreenConnect is not used by the business, block *.screenconnect.com relay traffic at the perimeter

Longer-term hardening

  • Allowlist only approved RMM tools with application control and audit RMM software inventory
  • Restrict outbound RMM relay traffic to sanctioned instances only (per CISA AA23-025A)
  • Train users on fake payment-receipt and wire-transfer lures and on verifying brand senders via SPF/DKIM/DMARC alignment

Timeline of ScreenConnect Client Abused by Attackers via Mejuri-Themed

  • Start of the financially motivated help-desk/refund-scam phishing campaign later described by CISA (AA23-025A), delivering ScreenConnect and AnyDesk as portable executables to victims (CISA: activity 'since June 2022').
  • CISA, NSA and MS-ISAC publish AA23-025A on phishing campaigns delivering ScreenConnect and AnyDesk portable executables for refund scams.
  • Abnormal Security reports a ScreenConnect abuse campaign (fake Zoom/Teams installers, Zoom.ClientSetup.exe) targeting 900+ organizations.
  • SANS ISC Diary 33388 (Xavier Mertens) published with IOCs; last updated 2026-10-01 05:32 UTC.
  • Linked ScreenConnect.ClientSetup.exe hosted on thelittlecupandsaucer.com.au found to be a validly ConnectWise-signed client with an embedded config for instance v2e3e2 (relay port 443); unknown on VirusTotal.
  • Phishing email spoofing contact@mejuri.com, subject 'EFT Wire Transfer', claiming $5745.65 received, observed and analyzed.

Sources cited for ScreenConnect Client Abused by Attackers via Mejuri-Themed

More in phishing

Detection coverage for TL-2026-2826

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2826 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats