Threat reportPhishingTL-2026-2931

Phishing Campaign Abuses Legitimate ScreenConnect Client for Remote Access via Fake Payment Notification

mediumACTIVE

Phishing Campaign Abuses Legitimate ScreenConnect Client for (TL-2026-2931) is a medium-severity phishing campaign, first published 2026-10-05. It has no confirmed attribution, affects ConnectWise ScreenConnect (legitimate client abused; no vulnerability, maps to 5 MITRE ATT&CK techniques (T1036, T1204.001, T1204.002), and is covered by 9 detection rules and 10 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-2931

Threat ID
TL-2026-2931
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
10

Malware and tooling in Phishing Campaign Abuses Legitimate ScreenConnect Client for

Malware and tooling: ConnectWise - S0591, ConnectWise ScreenConnect, ScreenConnect

How Phishing Campaign Abuses Legitimate ScreenConnect Client for works

A phishing email posing as an 'EFT Wire Transfer' payment notification ($5,745.65) links to ScreenConnect.ClientSetup.exe, a genuine, validly signed ConnectWise ScreenConnect installer preconfigured to connect to an attacker-operated cloud relay instance (instance-v2e3e2-relay.screenconnect.com:443). No malware family is used; the legitimate remote-access function provides the foothold. Observed as a single attempt on 2026-10-01 with no confirmed victims.

On 2026-10-01 Xavier Mertens of the SANS Internet Storm Center (diary #33388) documented a phishing email sent from contact@mejuri.com with the subject 'EFT Wire Transfer'. The body claimed a payment of $5,745.65 had been received and told the recipient to click a link to view order information 'in PDF'. The link pointed to https://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, which is a real PE file rather than a PDF, so the lure relies on file-type masquerading and user execution.

The downloaded binary is an unmodified ConnectWise ScreenConnect client installer. Its Authenticode signature is valid (ConnectWise, LLC, issued via DigiCert G4 Code Signing CA1) and no tampering was detected. At analysis time the file was unknown on VirusTotal. Extraction of the embedded PE configuration showed a relay host of instance-v2e3e2-relay.screenconnect.com on port 443, instance ID v2e3e2 (ConnectWise cloud), and an RSA-2048 instance public key whose SHA-256 begins 16b1cec1 and ends 9b00ead7 (the source abbreviates the value). The ISC characterised the target as an attacker-operated test account. Once installed, the client registers with that attacker-controlled instance, giving the operator remote-access capability equivalent to an IT-support session.

Detection is difficult because the suspicious behaviour comes from the product's intended remote-access function, not from an altered binary: the signature validates and the relay is a legitimate ConnectWise cloud hostname. Defenders should hunt on unsanctioned ScreenConnect installs, unknown relay instance IDs (instance-<id>-relay.screenconnect.com), and executable downloads from untrusted sources. The same pattern (signed ScreenConnect installers bound to trial/free cloud instances) has been documented in other campaigns using app-store, meeting-invitation and document-viewer lures (LevelBlue SpiderLabs, Abnormal), but those are separate campaigns and no link to this one is established. The Cyber Security News article (2026-10-05) and the ISC both describe a single observed attempt; no victim count, data theft or actor attribution is reported. The LOLRMM project is cited as the broader inventory of RMM tools abused this way. A phone number (+1(332)638474823) was also reported in the lure.

MITRE ATT&CK techniques used in TL-2026-2931

Defense Evasion

T1036 Masquerading

Execution

T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Command and Control

T1219.002 Remote Access Tools: Remote Desktop Software

Initial Access

T1566.002 Phishing: Spearphishing Link

Affected products and versions in Phishing Campaign Abuses Legitimate ScreenConnect Client for

  • ConnectWise — ScreenConnect (legitimate client abused; no vulnerability involved)

Remediation for Phishing Campaign Abuses Legitimate ScreenConnect Client for

Immediate actions

  • Search email gateway and proxy logs for sender contact@mejuri.com, subject 'EFT Wire Transfer', and downloads from thelittlecupandsaucer.com.au
  • Hunt endpoints for ScreenConnect.ClientSetup.exe and ScreenConnect client services connecting to instance-v2e3e2-relay.screenconnect.com (instance ID v2e3e2)
  • Isolate and reimage any host where the client was installed and a session was established

Workarounds

  • Application control (WDAC/AppLocker) policy that permits ScreenConnect only for the organisation's own signed instance
  • Do not block by Authenticode signature alone; the binary is genuinely signed by ConnectWise, LLC

Longer-term hardening

  • Allowlist sanctioned ScreenConnect instance IDs/relay hostnames and alert on any other instance-*-relay.screenconnect.com
  • Inventory approved RMM tools (see LOLRMM) and block or alert on all others
  • Block executable downloads from untrusted sources at browser/proxy and flag executables served for PDF-themed links
  • Train staff that payment notifications linking to .exe files are phishing

Timeline of Phishing Campaign Abuses Legitimate ScreenConnect Client for

  • SANS ISC publishes diary #33388 documenting the abuse and recommending monitoring of suspicious RMM deployments and blocking executable downloads from untrusted sources
  • Embedded configuration shows relay instance-v2e3e2-relay.screenconnect.com:443, instance ID v2e3e2 (ConnectWise cloud), RSA-2048 instance key; assessed as an attacker-operated test account
  • Binary is an unmodified ConnectWise ScreenConnect installer with a valid Authenticode signature (ConnectWise, LLC via DigiCert G4 Code Signing CA1); no tampering detected
  • Email link resolves to https://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, a real PE file (not a PDF); unknown on VirusTotal at analysis time
  • ISC handler Xavier Mertens observes a phishing email from contact@mejuri.com, subject 'EFT Wire Transfer', claiming a $5,745.65 payment and urging the recipient to click to view order information in PDF
  • Cyber Security News reports the campaign; a single observed attempt, no confirmed victims or data theft reported

Sources cited for Phishing Campaign Abuses Legitimate ScreenConnect Client for

Detection coverage for TL-2026-2931

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2931 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats