# Phishing Campaign Abuses Legitimate ScreenConnect Client for Remote Access via Fake Payment Notification

> A phishing email posing as an 'EFT Wire Transfer' payment notification ($5,745.65) links to ScreenConnect.ClientSetup.exe, a genuine, validly signed ConnectWise ScreenConnect installer preconfigured to connect to an attacker-operated cloud relay instance (instance-v2e3e2-relay.screenconnect.com:443). No malware family is used; the legitimate remote-access function provides the foothold. Observed as a single attempt on 2026-10-01 with no confirmed victims.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2931
- **ID:** TL-2026-2931
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-01 Xavier Mertens of the SANS Internet Storm Center (diary #33388) documented a phishing email sent from contact@mejuri.com with the subject 'EFT Wire Transfer'. The body claimed a payment of $5,745.65 had been received and told the recipient to click a link to view order information 'in PDF'. The link pointed to https://thelittlecupandsaucer.com.au/ScreenConnect.ClientSetup.exe, which is a real PE file rather than a PDF, so the lure relies on file-type masquerading and user execution.

The downloaded binary is an unmodified ConnectWise ScreenConnect client installer. Its Authenticode signature is valid (ConnectWise, LLC, issued via DigiCert G4 Code Signing CA1) and no tampering was detected. At analysis time the file was unknown on VirusTotal. Extraction of the embedded PE configuration showed a relay host of instance-v2e3e2-relay.screenconnect.com on port 443, instance ID v2e3e2 (ConnectWise cloud), and an RSA-2048 instance public key whose SHA-256 begins 16b1cec1 and ends 9b00ead7 (the source abbreviates the value). The ISC characterised the target as an attacker-operated test account. Once installed, the client registers with that attacker-controlled instance, giving the operator remote-access capability equivalent to an IT-support session.

Detection is difficult because the suspicious behaviour comes from the product's intended remote-access function, not from an altered binary: the signature validates and the relay is a legitimate ConnectWise cloud hostname. Defenders should hunt on unsanctioned ScreenConnect installs, unknown relay instance IDs (instance-<id>-relay.screenconnect.com), and executable downloads from untrusted sources. The same pattern (signed ScreenConnect installers bound to trial/free cloud instances) has been documented in other campaigns using app-store, meeting-invitation and document-viewer lures (LevelBlue SpiderLabs, Abnormal), but those are separate campaigns and no link to this one is established. The Cyber Security News article (2026-10-05) and the ISC both describe a single observed attempt; no victim count, data theft or actor attribution is reported. The LOLRMM project is cited as the broader inventory of RMM tools abused this way. A phone number (+1(332)638474823) was also reported in the lure.

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1204.002 User Execution: Malicious File
- T1036 Masquerading
- T1219.002 Remote Access Tools: Remote Desktop Software

## Sources

- [SANS ISC Diary #33388 - ScreenConnect client abuse (Xavier Mertens)](https://isc.sans.edu/diary/33388)
- [Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing](https://cybersecuritynews.com/screenconnect-tool/)
- [LevelBlue SpiderLabs - Beyond Fake Updates: App Store-Themed Phishing to Large-Scale Distribution of ScreenConnect](https://www.levelblue.com/blogs/spiderlabs-blog/beyond-fake-updates-from-application-store-themed-phishing-to-large-scale-distribution-of-screenconnect)
- [Abnormal AI - ScreenConnect Abuse Phishing Campaign](https://abnormal.ai/blog/screenconnect-abuse-phishing-campaign)
- [LOLRMM - Living Off the Land Remote Monitoring and Management tools](https://lolrmm.io/)
- [MITRE ATT&CK T1219.002 Remote Desktop Software](https://attack.mitre.org/techniques/T1219/002/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2931
