Hackers Abuse ConnectWise to Hide Malware

Hackers Abuse ConnectWise to Hide Malware

Threat actors are abusing ConnectWise remote access applications through a technique called Authenticode stuffing to hide malicious code and bypass security checks. G Data warns that hackers are using modified ConnectWise clients to deliver malware and impersonate legitimate updates, posing significant security risks. #ConnectWise #AuthenticodeStuffing

Keypoints

  • Threat actors are exploiting vulnerabilities in ConnectWise remote access applications to hide malicious code.
  • Authenticode stuffing involves inserting malicious payloads into the certificate table, avoiding hash verification.
  • Hackers use modified ConnectWise clients to deliver malware and conceal their installations under false pretenses.
  • G Data discovered attacks since March 2025, including masquerading as AI image converters and fake Windows updates.
  • ConnectWise responded by revoking impacted signatures, but the technique highlights ongoing security challenges.

Read More: https://www.securityweek.com/hackers-abuse-connectwise-to-hide-malware/