Hackers turn ScreenConnect into malware using Authenticode stuffing

Hackers turn ScreenConnect into malware using Authenticode stuffing

Cybercriminals are exploiting the ConnectWise ScreenConnect installer by modifying its cryptographic signature to embed malicious configurations, turning it into a remote access malware. Despite the digital signature remaining valid, the altered installers facilitate stealthy device access and phishing attacks, with cleanup efforts led by ConnectWise revoking compromised certificates. #ConnectWise #Authenticode #RemoteAccessMalware

Keypoints

  • Threat actors modify the Authenticode signature of ConnectWise ScreenConnect to insert malicious configuration data.
  • Malicious binaries with identical hashes are distributed via phishing campaigns on forums like BleepingComputer and Reddit.
  • Attackers use fake Windows Update screens and disguise malware as legitimate software to deceive users.
  • ConnectWise responded by revoking the compromised code signing certificates, but threats persist.
  • Similar tactics are employed on other enterprise tools like SonicWall VPN clients to steal credentials.

Read More: https://www.bleepingcomputer.com/news/security/hackers-turn-screenconnect-into-malware-using-authenticode-stuffing/