ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
ScreenConnect Client Abused by Attackers via Mejuri-Themed (TL-2026-2826) is a medium-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects ConnectWise ScreenConnect (abused as legitimate RMM; no vulnerability), maps to 9 MITRE ATT&CK techniques (T1036, T1071.001, T1090), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2826
- Threat ID
- TL-2026-2826
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- retail, finance, general enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in ScreenConnect Client Abused by Attackers via Mejuri-Themed
Malware and tooling: ConnectWise - S0591, ScreenConnect, ScreenConnect relay
A phishing email impersonating jewelry brand Mejuri (fake $5,745.65 'EFT Wire Transfer' payment receipt) lures recipients to download ScreenConnect.ClientSetup.exe from a compromised Australian domain. The file is a genuine, validly ConnectWise-signed ScreenConnect client preconfigured to call back to an attacker-operated ConnectWise-hosted instance via a relay on port 443.
How ScreenConnect Client Abused by Attackers via Mejuri-Themed works
On 2026-10-01 SANS ISC handler Xavier Mertens documented a phishing email spoofing the sender contact@mejuri.com with the subject 'EFT Wire Transfer'. The body claims a payment of $5745.65 was received and urges the recipient to view order information; it also lists a phone number (+1(332)638474823), a typical callback-phishing/refund-scam element. The call-to-action points to hxxps://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, a download hosted on a .com.au domain that appears to be a compromised, unrelated website.
The downloaded executable is not tampered malware. It is a legitimate ScreenConnect client installer signed by 'ConnectWise, LLC' (DigiCert G4 Code Signing CA1) whose Authenticode digest matches and which has no overlay. The attacker-specific part is the embedded client configuration, extracted from the PE: relay instance-v2e3e2-relay.screenconnect.com, port 443, instance ID v2e3e2 (ConnectWise-hosted cloud instance), and an RSA-2048 instance key (SHA256 beginning 16b1cec1, ending 9b00ead7; the diary shows a truncated value). Per the analyst, this is a client preconfigured to call back to a (trial/test) account operated by the attacker. At the time of analysis the sample was unknown on VirusTotal.
Abusing a signed, commercially available RMM tool lets the actor skip custom malware: the valid signature and the trusted screenconnect.com relay domain blend into normal enterprise traffic, and once installed the actor has interactive remote control of the endpoint. The source gives no attribution, malware family, CVE, or follow-on activity. The pattern matches earlier RMM-abuse campaigns described by CISA/NSA/MS-ISAC in advisory AA23-025A (ScreenConnect and AnyDesk delivered via phishing for refund scams) and by Abnormal Security in 2025 (ScreenConnect delivered as fake Zoom/Teams installers). Defenders should treat any unsanctioned ScreenConnect client, especially one calling an instance not owned by the organization, as a potential intrusion.
MITRE ATT&CK techniques used in TL-2026-2826
Defense Evasion
T1036 Masquerading; T1684.001 Impersonation
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1219.002 Remote Desktop Software
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Initial Access
Resource Development
Affected products and versions in ScreenConnect Client Abused by Attackers via Mejuri-Themed
- ConnectWise — ScreenConnect (abused as legitimate RMM; no vulnerability)
Remediation for ScreenConnect Client Abused by Attackers via Mejuri-Themed
Immediate actions
- Block/alert on DNS and TLS connections to instance-v2e3e2-relay.screenconnect.com and any ScreenConnect instance ID not owned by the organization
- Block thelittlecupandsaucer.com.au and the URL path /ScreenConnect.ClientSetup.exe at web proxy/DNS
- Search email logs for sender contact@mejuri.com with subject 'EFT Wire Transfer' and purge matching messages
- Hunt endpoints for ScreenConnect.ClientSetup.exe executions and ScreenConnect client services/ClickOnce artifacts, then isolate and reimage hosts that ran it
Workarounds
- Where ScreenConnect is not used by the business, block *.screenconnect.com relay traffic at the perimeter
Longer-term hardening
- Allowlist only approved RMM tools with application control and audit RMM software inventory
- Restrict outbound RMM relay traffic to sanctioned instances only (per CISA AA23-025A)
- Train users on fake payment-receipt and wire-transfer lures and on verifying brand senders via SPF/DKIM/DMARC alignment
Timeline of ScreenConnect Client Abused by Attackers via Mejuri-Themed
- Start of the financially motivated help-desk/refund-scam phishing campaign later described by CISA (AA23-025A), delivering ScreenConnect and AnyDesk as portable executables to victims (CISA: activity 'since June 2022').
- CISA, NSA and MS-ISAC publish AA23-025A on phishing campaigns delivering ScreenConnect and AnyDesk portable executables for refund scams.
- Abnormal Security reports a ScreenConnect abuse campaign (fake Zoom/Teams installers, Zoom.ClientSetup.exe) targeting 900+ organizations.
- SANS ISC Diary 33388 (Xavier Mertens) published with IOCs; last updated 2026-10-01 05:32 UTC.
- Linked ScreenConnect.ClientSetup.exe hosted on thelittlecupandsaucer.com.au found to be a validly ConnectWise-signed client with an embedded config for instance v2e3e2 (relay port 443); unknown on VirusTotal.
- Phishing email spoofing contact@mejuri.com, subject 'EFT Wire Transfer', claiming $5745.65 received, observed and analyzed.
Sources cited for ScreenConnect Client Abused by Attackers via Mejuri-Themed
- ScreenConnect Client (Ab)used by Attackers - SANS ISC Diary (Xavier Mertens)
- SANS ISC Diary 33388 (canonical page)
- CISA/NSA/MS-ISAC AA23-025A: Protecting Against Malicious Use of Remote Monitoring and Management Software
- Abnormal Security: ScreenConnect Abuse Phishing Campaign
- UCSF IT: ScreenConnect-themed credential phishing (March 2024)
- SOC Prime: Phishing emails disguised as transaction receipts delivering ScreenConnect
More in phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
- Fake American Express "non-compliance" card-lock phishing campaign targets Australians
Detection coverage for TL-2026-2826
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2826 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.