Cybercriminals are exploiting the ConnectWise ScreenConnect installer by modifying its cryptographic signature to embed malicious configurations, turning it into a remote access malware. Despite the digital signature remaining valid, the altered installers facilitate stealthy device access and phishing attacks, with cleanup efforts led by ConnectWise revoking compromised certificates. #ConnectWise #Authenticode #RemoteAccessMalware
Keypoints
- Threat actors modify the Authenticode signature of ConnectWise ScreenConnect to insert malicious configuration data.
- Malicious binaries with identical hashes are distributed via phishing campaigns on forums like BleepingComputer and Reddit.
- Attackers use fake Windows Update screens and disguise malware as legitimate software to deceive users.
- ConnectWise responded by revoking the compromised code signing certificates, but threats persist.
- Similar tactics are employed on other enterprise tools like SonicWall VPN clients to steal credentials.