Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
LevelBlue OpsCTI identified a large-scale phishing campaign that impersonates trusted apps and services to trick victims into installing unauthorized ConnectWise ScreenConnect clients through fake update and installation flows. The campaign uses compromised sites, attacker-controlled hosts, Amazon S3, Cloudflare R2, Telegram telemetry, and reused infrastructure artifacts to deliver remote access payloads and expand hunting opportunities. #ConnectWiseScreenConnect #GoogleMeet #MicrosoftStore #AppleAppStore #TelegramBotAPI

Keypoints

  • Phishing pages impersonate Google Meet, Microsoft Store, Apple App Store, Adobe Acrobat, Microsoft Teams, Zoom, Docusign, and other trusted brands.
  • The main lure is a fake software update sequence that leads victims to install a preconfigured ConnectWise ScreenConnect client.
  • Once installed, the client registers with an attacker-controlled ScreenConnect instance, granting remote access to compromised systems.
  • The campaign delivers payloads through compromised websites, attacker-controlled infrastructure, Amazon S3 buckets, and Cloudflare R2 object storage.
  • Infrastructure reuse is extensive, including repeated directory structures, static HTTP resource hashes, reverse DNS artifacts, and shared scripts.
  • Victim profiling and telemetry collection are common, with data sent to hard-coded Telegram bots before or during payload delivery.
  • Some variants use anti-automation checks, OS validation, hidden iframes, batch files, UAC elevation, and silent MSI installation to complete the infection chain.

MITRE Techniques

  • [T1583.006] Acquire Infrastructure: Web Services – The actor used cloud and hosted services to support delivery and hosting (‘distributed through attacker-controlled infrastructure, Amazon S3 buckets, and Cloudflare R2 object storage’).
  • [T1608.004] Stage Capabilities: Drive-by Target – Victims were steered into staged web flows that prepared the payload download (‘fake software update sequence that persuades victims to install a preconfigured ConnectWise ScreenConnect client’).
  • [T1189] Drive-by Compromise – Visiting the lure pages triggered automatic redirection and staged download behavior (‘Upon page load… invoking the forceDownload() function’).
  • [T1566] Phishing – The campaign used fake meeting, update, and document pages to lure victims (‘large-scale phishing campaign leveraging a new social engineering method’).
  • [T1204.002] User Execution: Malicious File – The victim was induced to open and run the downloaded installer or batch file (‘install a preconfigured ConnectWise ScreenConnect client’ and ‘download.php script functions as… the payload delivery mechanism’).
  • [T1059.001] Command and Scripting Interpreter: PowerShell – PowerShell was used to download and launch payloads (‘Invoke-WebRequest -Uri the URL -OutFile’).
  • [T1059.003] Command and Scripting Interpreter: Windows Command Shell – Batch scripts launched commands and installers (‘start “” /wait /b msiexec /i “%FILE%” /quiet /qn /norestart’).
  • [T1082] System Information Discovery – The phishing scripts collected host and browser details (‘collect extensive host and browser telemetry’ including IP address, OS, device type, screen resolution, and time zone).
  • [T1036.005] Match Legitimate Resource Name or Location – The actor impersonated trusted brands and used lookalike paths to appear legitimate (‘impersonates the Microsoft Store and Apple App Store’ and ‘closely imitate the Google Meet pre-join experience’).
  • [T1218.007] System Binary Proxy Execution: Msiexec – MSI payloads were installed through msiexec to blend in with legitimate software installation (‘start “” /wait /b msiexec /i “%FILE%” /quiet /qn /norestart’).
  • [T1684.001] Social Engineering: Impersonation – The pages impersonated software services, invitations, and document portals (‘impersonating the Microsoft Store and Apple App Store’ and ‘fake software update notification’).
  • [T1105] Ingress Tool Transfer – Payloads were retrieved from remote infrastructure before installation (‘silently initiates retrieval of ScreenConnect.ClientSetup.exe’ and downloads from S3/R2 endpoints).
  • [T1219.002] Remote Access Tools: Remote Desktop Software – The campaign delivered ScreenConnect clients for remote control (‘deploy unauthorized ConnectWise ScreenConnect clients’ and ‘providing the threat actor with remote access’).

Indicators of Compromise

  • [URL ] Fake Google Meet lure – hxxps://stcdubai[.]com/googlemeet/, bestchoice.sa[.]com
  • [Domain ] Reused campaign and lure hosts – paperorbit[.]cloud, jumpingcloud[.]top, pixelio[.]site
  • [IP address ] Attacker-controlled infrastructure – 69.49.246[.]105, and other related hosting endpoints
  • [File hash ] Static HTTP resource hashes used for pivoting – 7fd3d2956d216c23e560f747d2ea30fb469986fac634ddc483e38bcca49bdd95, 9cc0dfa491f5eebdca6a351e699886946b0b96fdbcb7d454ea15af2fffdf6b93
  • [File hash ] Batch-file payload hashes – bc9bcb5915fdc314ed0b3de952c83b3380048c4ffd1bc3579b7e1badd7fa9181, C71DDFA376B2A86BAE93D46D997742502D127979A8774402C936EC6832BB91D0
  • [Filename ] ScreenConnect installers and staged payloads – ScreenConnect.ClientSetup.exe, ScreenConnect.ClientSetup.msi
  • [Filename ] Malicious batch payloads – INVOICE2515.bat, InviteJuly26.bat, and other themed .bat files
  • [URL ] Cloudflare R2 payload delivery – hxxps://pub-d7ab35315be7454889d8f97c69fc2074.r2.dev/SSA_STATEMENT_EN_US.zip, hxxps://pub-39190877e0004c3a84a95c22db10d23b.r2.dev/Secure_Document_Viewer.msi
  • [URL ] AWS S3 payload delivery – hxxps://eobtdk.s3.us-east-2.amazonaws.com/ScreenConnect.ClientSetup.msi, hxxps://kilodz.s3.us-east-2.amazonaws.com/ScreenConnect.ClientSetup.msi
  • [Hostname ] ScreenConnect relay hostname pattern – instance-XXXXXX-relay.screenconnect[.]com, *.smartpocketmoney[.]com
  • [Telegram Bot Token ] Telemetry delivery to operator bots – 8918656905:AAHsvi-QVq2HcIx0mcyR62tBzzjNFk-_ags, 8492930076:AAGoNZ9WBED4lDgombN5eldcKfeqsaSdFjM


Read more: https://www.levelblue.com/blogs/spiderlabs-blog/beyond-fake-updates-from-application-store-themed-phishing-to-large-scale-distribution-of-screenconnect