Threat reportPhishingTL-2026-2931
Phishing Campaign Abuses Legitimate ScreenConnect Client for Remote Access via Fake Payment Notification
Phishing Campaign Abuses Legitimate ScreenConnect Client for (TL-2026-2931) is a medium-severity phishing campaign, first published 2026-10-05. It has no confirmed attribution, affects ConnectWise ScreenConnect (legitimate client abused; no vulnerability, maps to 5 MITRE ATT&CK techniques (T1036, T1204.001, T1204.002), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-2931
- Threat ID
- TL-2026-2931
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Phishing Campaign Abuses Legitimate ScreenConnect Client for
Malware and tooling: ConnectWise - S0591, ConnectWise ScreenConnect, ScreenConnect
How Phishing Campaign Abuses Legitimate ScreenConnect Client for works
A phishing email posing as an 'EFT Wire Transfer' payment notification ($5,745.65) links to ScreenConnect.ClientSetup.exe, a genuine, validly signed ConnectWise ScreenConnect installer preconfigured to connect to an attacker-operated cloud relay instance (instance-v2e3e2-relay.screenconnect.com:443). No malware family is used; the legitimate remote-access function provides the foothold. Observed as a single attempt on 2026-10-01 with no confirmed victims.
On 2026-10-01 Xavier Mertens of the SANS Internet Storm Center (diary #33388) documented a phishing email sent from contact@mejuri.com with the subject 'EFT Wire Transfer'. The body claimed a payment of $5,745.65 had been received and told the recipient to click a link to view order information 'in PDF'. The link pointed to https://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, which is a real PE file rather than a PDF, so the lure relies on file-type masquerading and user execution.
The downloaded binary is an unmodified ConnectWise ScreenConnect client installer. Its Authenticode signature is valid (ConnectWise, LLC, issued via DigiCert G4 Code Signing CA1) and no tampering was detected. At analysis time the file was unknown on VirusTotal. Extraction of the embedded PE configuration showed a relay host of instance-v2e3e2-relay.screenconnect.com on port 443, instance ID v2e3e2 (ConnectWise cloud), and an RSA-2048 instance public key whose SHA-256 begins 16b1cec1 and ends 9b00ead7 (the source abbreviates the value). The ISC characterised the target as an attacker-operated test account. Once installed, the client registers with that attacker-controlled instance, giving the operator remote-access capability equivalent to an IT-support session.
Detection is difficult because the suspicious behaviour comes from the product's intended remote-access function, not from an altered binary: the signature validates and the relay is a legitimate ConnectWise cloud hostname. Defenders should hunt on unsanctioned ScreenConnect installs, unknown relay instance IDs (instance-<id>-relay.screenconnect.com), and executable downloads from untrusted sources. The same pattern (signed ScreenConnect installers bound to trial/free cloud instances) has been documented in other campaigns using app-store, meeting-invitation and document-viewer lures (LevelBlue SpiderLabs, Abnormal), but those are separate campaigns and no link to this one is established. The Cyber Security News article (2026-10-05) and the ISC both describe a single observed attempt; no victim count, data theft or actor attribution is reported. The LOLRMM project is cited as the broader inventory of RMM tools abused this way. A phone number (+1(332)638474823) was also reported in the lure.
MITRE ATT&CK techniques used in TL-2026-2931
Defense Evasion
Execution
T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
Command and Control
T1219.002 Remote Access Tools: Remote Desktop Software
Initial Access
Affected products and versions in Phishing Campaign Abuses Legitimate ScreenConnect Client for
- ConnectWise — ScreenConnect (legitimate client abused; no vulnerability involved)
Remediation for Phishing Campaign Abuses Legitimate ScreenConnect Client for
Immediate actions
- Search email gateway and proxy logs for sender contact@mejuri.com, subject 'EFT Wire Transfer', and downloads from thelittlecupandsaucer.com.au
- Hunt endpoints for ScreenConnect.ClientSetup.exe and ScreenConnect client services connecting to instance-v2e3e2-relay.screenconnect.com (instance ID v2e3e2)
- Isolate and reimage any host where the client was installed and a session was established
Workarounds
- Application control (WDAC/AppLocker) policy that permits ScreenConnect only for the organisation's own signed instance
- Do not block by Authenticode signature alone; the binary is genuinely signed by ConnectWise, LLC
Longer-term hardening
- Allowlist sanctioned ScreenConnect instance IDs/relay hostnames and alert on any other instance-*-relay.screenconnect.com
- Inventory approved RMM tools (see LOLRMM) and block or alert on all others
- Block executable downloads from untrusted sources at browser/proxy and flag executables served for PDF-themed links
- Train staff that payment notifications linking to .exe files are phishing
Timeline of Phishing Campaign Abuses Legitimate ScreenConnect Client for
- SANS ISC publishes diary #33388 documenting the abuse and recommending monitoring of suspicious RMM deployments and blocking executable downloads from untrusted sources
- Embedded configuration shows relay instance-v2e3e2-relay.screenconnect.com:443, instance ID v2e3e2 (ConnectWise cloud), RSA-2048 instance key; assessed as an attacker-operated test account
- Binary is an unmodified ConnectWise ScreenConnect installer with a valid Authenticode signature (ConnectWise, LLC via DigiCert G4 Code Signing CA1); no tampering detected
- Email link resolves to https://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, a real PE file (not a PDF); unknown on VirusTotal at analysis time
- ISC handler Xavier Mertens observes a phishing email from contact@mejuri.com, subject 'EFT Wire Transfer', claiming a $5,745.65 payment and urging the recipient to click to view order information in PDF
- Cyber Security News reports the campaign; a single observed attempt, no confirmed victims or data theft reported
Sources cited for Phishing Campaign Abuses Legitimate ScreenConnect Client for
- SANS ISC Diary #33388 - ScreenConnect client abuse (Xavier Mertens)
- Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing
- LevelBlue SpiderLabs - Beyond Fake Updates: App Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
- Abnormal AI - ScreenConnect Abuse Phishing Campaign
- LOLRMM - Living Off the Land Remote Monitoring and Management tools
- MITRE ATT&CK T1219.002 Remote Desktop Software
Detection coverage for TL-2026-2931
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2931 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.