Huntress observed a rise in rogue ScreenConnect installations in 2025, with threat actors using social engineering lures (invoices, invitations, Social Security statements) to get victims to download renamed ScreenConnect clients. Attackers abused domains and dynamic DNS services to host installers and C2, and Huntress recommends auditing RMMs, reviewing logs, and using domain reputation/callback analysis to detect malicious instances. #ScreenConnect #Huntress
Keypoints
- Huntress SOC documented an uptick in rogue ScreenConnect infections across 2025, often delivered via phishing and social-engineering lures.
- Threat actors use RMM tools (primarily ScreenConnect) to gain access, blend in, move laterally, and maintain persistence.
- Common lures observed include Social Security statement-themed executables, event/invitation-themed executables, and invoice/statement-themed executables.
- Top malicious domains tied to these attacks include 0bd0[.]adrsxpjm0rga0n[.]de, rok628[.]mxhelp[.]top, yoc736[.]ikhelp[.]top, lory473[.]top, and slplegalfinance[.]com.
- Multiple incidents reused identical SHA256 hashes and filenames across different victim accounts, indicating campaign reuse of infrastructure and payloads.
- Dynamic DNS services (e.g., subjent25[.]zapto[.]org) were abused to hide infrastructure and enable widespread domain reuse across victims.
- Huntress reports ScreenConnect accounts for 74.5% of observed RMM abuse; recommended mitigations include auditing/monitoring RMMs, reviewing execution logs, updating RMM software, and using EDR to analyze callback domains.
MITRE Techniques
- [T1566 ] Phishing – Use of phishing emails and landing pages to deliver lures and downloads (‘phishing email’ / ‘targeted phishing attack’).
- [T1204 ] User Execution – Victims were socially engineered to download and execute renamed ScreenConnect installers (e.g., ‘executing the executable Social_Security_Statements_April2025_Updates.Client.exe’).
- [T1105 ] Ingress Tool Transfer – Attackers deployed or installed attacker-controlled RMM software onto victim machines (‘deploying and installing an attacker’s preferred RMM onto victims’ computers’).
- [T1021 ] Remote Services – Abuse of remote monitoring and management tools to gain remote access, move laterally, and maintain persistence (‘use RMMs like ScreenConnect, TeamViewer, LogMeIn … to gain access, blend in, move laterally, and maintain persistence’).
- [T1071 ] Application Layer Protocol – Malicious installations performed callbacks to attacker-controlled domains and abused dynamic DNS for C2 infrastructure (‘inspecting the installation’s call-back to the specific domain managing it’ / ‘dynamic DNS domain services’).
Indicators of Compromise
- [Domain ] Domains hosting rogue ScreenConnect installers and landing pages – 0bd0[.]adrsxpjm0rga0n[.]de, lory473[.]top, and 3 more known malicious domains (rok628[.]mxhelp[.]top, yoc736[.]ikhelp[.]top, slplegalfinance[.]com).
- [SHA256 Hash ] Hashes of observed renamed ScreenConnect executables – 44b6b1de9a618c97788631bc89372435a6ea0357e50497152a67219dea400209, bdbac9fe9e7aca3a03d55867eddd905c4e222f3045b0015b823df4f034ee007a, and 3 more top hashes.
- [Filename ] Executable lure filenames used in attacks – RevisedStatementJAN2025.exe, Invitation.ClientSetup.exe, and other lures such as Social_Security_Statement_Viewer.exe or INVO_[variation].exe.
- [Dynamic DNS ] Abused dynamic DNS domains and services used for C2 and to mask infrastructure – subjent25[.]zapto[.]org, sans[.]infosedi[.]de (Zapto and similar dynamic DNS providers).
Read more: https://www.huntress.com/blog/rogue-screenconnect-social-engineering-tactics-2025