Dev News Daily ENDE

Phishing ships a genuine signed ScreenConnect client wired to the attacker

A diary entry on the SANS Internet Storm Center, published on 1 October by handler Xavier Mertens, describes a phishing campaign that needs no malware of its own. The attacker sends a legitimate remote-support tool, configured to connect to an account they control.

The email was simple: a notice that a payment of $5,745.65 had been received, with a link to cancel it if it was not authorised. The link pointed to a file named ScreenConnect.ClientSetup.exe on a compromised third-party website. According to the diary, the email passed basic security controls.

Analysis showed the file was not modified malware but a genuine ScreenConnect client, preconfigured to call back to a test account operated by the attacker. It was signed by ConnectWise, LLC, the Authenticode digest matched the signed digest exactly, and nothing had been appended to the file or injected into its certificate table. The file was unknown to VirusTotal when examined. Once installed, a tool like this gives the operator remote control of the machine through a trusted, signed program.

Mertens notes that modern browsers will usually flag a downloaded executable as suspicious, but describes remote monitoring and management tools in general as a gold mine for attackers: easy to deploy and trusted by most users. He points to the LOLRMM project, which catalogues such tools in the same way that LOLBAS catalogues abusable Windows binaries.

Phishing ships a genuine signed ScreenConnect client wired to the attacker
Phishing ships a genuine signed ScreenConnect client wired to the attacker — Dev News Daily

Why it matters

Defences that look for malicious or tampered files have nothing to find here: the signature is valid and the binary is what it claims to be. The practical controls are about which remote-access tools are allowed at all. Organisations that use one RMM product can block or alert on the installation of others, and on connections to vendor relay infrastructure that the business does not use.

Primary source
SANS Internet Storm Center
https://isc.sans.edu/diary/rss/33388
Written by Victoria Shinder.