LevelBlue OpsCTI identified a large-scale phishing campaign that impersonates trusted apps and services to trick victims into installing unauthorized ConnectWise ScreenConnect clients through fake update and installation flows. The campaign uses compromised sites, attacker-controlled hosts, Amazon S3, Cloudflare R2, Telegram telemetry, and reused infrastructure artifacts to deliver remote access payloads and expand hunting opportunities. #ConnectWiseScreenConnect #GoogleMeet #MicrosoftStore #AppleAppStore #TelegramBotAPI
Keypoints
- Phishing pages impersonate Google Meet, Microsoft Store, Apple App Store, Adobe Acrobat, Microsoft Teams, Zoom, Docusign, and other trusted brands.
- The main lure is a fake software update sequence that leads victims to install a preconfigured ConnectWise ScreenConnect client.
- Once installed, the client registers with an attacker-controlled ScreenConnect instance, granting remote access to compromised systems.
- The campaign delivers payloads through compromised websites, attacker-controlled infrastructure, Amazon S3 buckets, and Cloudflare R2 object storage.
- Infrastructure reuse is extensive, including repeated directory structures, static HTTP resource hashes, reverse DNS artifacts, and shared scripts.
- Victim profiling and telemetry collection are common, with data sent to hard-coded Telegram bots before or during payload delivery.
- Some variants use anti-automation checks, OS validation, hidden iframes, batch files, UAC elevation, and silent MSI installation to complete the infection chain.
MITRE Techniques
- [T1583.006] Acquire Infrastructure: Web Services – The actor used cloud and hosted services to support delivery and hosting (‘distributed through attacker-controlled infrastructure, Amazon S3 buckets, and Cloudflare R2 object storage’).
- [T1608.004] Stage Capabilities: Drive-by Target – Victims were steered into staged web flows that prepared the payload download (‘fake software update sequence that persuades victims to install a preconfigured ConnectWise ScreenConnect client’).
- [T1189] Drive-by Compromise – Visiting the lure pages triggered automatic redirection and staged download behavior (‘Upon page load… invoking the forceDownload() function’).
- [T1566] Phishing – The campaign used fake meeting, update, and document pages to lure victims (‘large-scale phishing campaign leveraging a new social engineering method’).
- [T1204.002] User Execution: Malicious File – The victim was induced to open and run the downloaded installer or batch file (‘install a preconfigured ConnectWise ScreenConnect client’ and ‘download.php script functions as… the payload delivery mechanism’).
- [T1059.001] Command and Scripting Interpreter: PowerShell – PowerShell was used to download and launch payloads (‘Invoke-WebRequest -Uri the URL -OutFile’).
- [T1059.003] Command and Scripting Interpreter: Windows Command Shell – Batch scripts launched commands and installers (‘start “” /wait /b msiexec /i “%FILE%” /quiet /qn /norestart’).
- [T1082] System Information Discovery – The phishing scripts collected host and browser details (‘collect extensive host and browser telemetry’ including IP address, OS, device type, screen resolution, and time zone).
- [T1036.005] Match Legitimate Resource Name or Location – The actor impersonated trusted brands and used lookalike paths to appear legitimate (‘impersonates the Microsoft Store and Apple App Store’ and ‘closely imitate the Google Meet pre-join experience’).
- [T1218.007] System Binary Proxy Execution: Msiexec – MSI payloads were installed through msiexec to blend in with legitimate software installation (‘start “” /wait /b msiexec /i “%FILE%” /quiet /qn /norestart’).
- [T1684.001] Social Engineering: Impersonation – The pages impersonated software services, invitations, and document portals (‘impersonating the Microsoft Store and Apple App Store’ and ‘fake software update notification’).
- [T1105] Ingress Tool Transfer – Payloads were retrieved from remote infrastructure before installation (‘silently initiates retrieval of ScreenConnect.ClientSetup.exe’ and downloads from S3/R2 endpoints).
- [T1219.002] Remote Access Tools: Remote Desktop Software – The campaign delivered ScreenConnect clients for remote control (‘deploy unauthorized ConnectWise ScreenConnect clients’ and ‘providing the threat actor with remote access’).
Indicators of Compromise
- [URL ] Fake Google Meet lure – hxxps://stcdubai[.]com/googlemeet/, bestchoice.sa[.]com
- [Domain ] Reused campaign and lure hosts – paperorbit[.]cloud, jumpingcloud[.]top, pixelio[.]site
- [IP address ] Attacker-controlled infrastructure – 69.49.246[.]105, and other related hosting endpoints
- [File hash ] Static HTTP resource hashes used for pivoting – 7fd3d2956d216c23e560f747d2ea30fb469986fac634ddc483e38bcca49bdd95, 9cc0dfa491f5eebdca6a351e699886946b0b96fdbcb7d454ea15af2fffdf6b93
- [File hash ] Batch-file payload hashes – bc9bcb5915fdc314ed0b3de952c83b3380048c4ffd1bc3579b7e1badd7fa9181, C71DDFA376B2A86BAE93D46D997742502D127979A8774402C936EC6832BB91D0
- [Filename ] ScreenConnect installers and staged payloads – ScreenConnect.ClientSetup.exe, ScreenConnect.ClientSetup.msi
- [Filename ] Malicious batch payloads – INVOICE2515.bat, InviteJuly26.bat, and other themed .bat files
- [URL ] Cloudflare R2 payload delivery – hxxps://pub-d7ab35315be7454889d8f97c69fc2074.r2.dev/SSA_STATEMENT_EN_US.zip, hxxps://pub-39190877e0004c3a84a95c22db10d23b.r2.dev/Secure_Document_Viewer.msi
- [URL ] AWS S3 payload delivery – hxxps://eobtdk.s3.us-east-2.amazonaws.com/ScreenConnect.ClientSetup.msi, hxxps://kilodz.s3.us-east-2.amazonaws.com/ScreenConnect.ClientSetup.msi
- [Hostname ] ScreenConnect relay hostname pattern – instance-XXXXXX-relay.screenconnect[.]com, *.smartpocketmoney[.]com
- [Telegram Bot Token ] Telemetry delivery to operator bots – 8918656905:AAHsvi-QVq2HcIx0mcyR62tBzzjNFk-_ags, 8492930076:AAGoNZ9WBED4lDgombN5eldcKfeqsaSdFjM