Threat actors are abusing ConnectWise remote access applications through a technique called Authenticode stuffing to hide malicious code and bypass security checks. G Data warns that hackers are using modified ConnectWise clients to deliver malware and impersonate legitimate updates, posing significant security risks. #ConnectWise #AuthenticodeStuffing
Keypoints
- Threat actors are exploiting vulnerabilities in ConnectWise remote access applications to hide malicious code.
- Authenticode stuffing involves inserting malicious payloads into the certificate table, avoiding hash verification.
- Hackers use modified ConnectWise clients to deliver malware and conceal their installations under false pretenses.
- G Data discovered attacks since March 2025, including masquerading as AI image converters and fake Windows updates.
- ConnectWise responded by revoking impacted signatures, but the technique highlights ongoing security challenges.
Read More: https://www.securityweek.com/hackers-abuse-connectwise-to-hide-malware/