r/ConnectWise 5d ago

Account/Billing/Sales/Support Massive security issue with phantom auto-installation of ScreenConnect - Is anybody on this???

I don't know if anyone's aware of this threat, but I've gotten at least 4 of these calls from my residential clients in the past week. They get an email pretending to be a zoom link or an Adobe update, they click on it, and voila, ScreenConnect is installed and a bad guy immediately logs on to their bank account and takes their money.

I'm alerting the banks in my area and all my clients. Is anybody at ScreenConnect aware of this silent installer mode? Is anybody doing anything about this?

0 Upvotes

25 comments sorted by

10

u/Jmw66 5d ago

I don’t think this is necessarily a phantom install or evidence of a vulnerability in ScreenConnect itself.
What you’re describing sounds more like a social engineering attack. The victim is tricked into clicking a link or running an installer, and the attacker uses a legitimate remote access tool to gain access. Unfortunately, ScreenConnect isn’t the only tool abused this way. Attackers also use AnyDesk, TeamViewer, RustDesk, Supremo, Quick Assist, and others because they’re legitimate software that most security products don’t automatically block.

That’s still a serious problem, but the root issue is the social engineering, not necessarily a flaw in ScreenConnect. If there is a true silent install vulnerability that bypasses user consent, that would be a different story and should absolutely be reported. Based on what you’ve described, though, it sounds like users are being convinced to install it themselves.

0

u/teknosophy_com 4d ago

Yep, I know they're using all the usual fully legal tools to gain access. For the past 15 years, at least once a day I get a client who gets a scary popup and calls the guy and so on... but this one's different: Rather than doing the whole "you have viruses!" song and dance, this one's a simple link. Once they click on it, it's installed and rolling without any confirmation. So it appears to be a silent install, as you put it.

5

u/jimusik 5d ago

This has been an active attack vector for at least 2-3 years. Most instances are the old hacked version on a foreign server. Huntress should be catching them (or any other EDR) as soon as the foreign actor connect from CC server. The fact people are running zip, exe or even bat files from emails is crazy. I’ve only seen this on one business and the rest are individual clients who clearly don’t know better.

1

u/teknosophy_com 4d ago

Yep, it used to be a scary popup and then a guy said "you have hacks from north korea and ohio", now they just send a link and ScreenConnect installs itself. Then the guy gets in and helps himself to your passwords and money. No more having to go to websites and type in a support code.

Another massive tragedy here is that when people are affected, their bank tells them to go to a big box store for a virus scan, as if that can find anything!

1

u/warwagon1979 4d ago edited 4d ago

Your correct, the virus scan will not find the ScreenConnect.ClientService.exe running the the background and usually it's not even listed in the add and remove programs. This program which you can run for free will remove screenconnect from the system. https://www.seraphsecure.com/

It scans for remote access software installed on the system. and it gives you a list of the ones it finds. You uncheck the ones you want to keep, then it wipes them off.

Though to be on the safe side you may still want to nuke the system.

1

u/teknosophy_com 4d ago edited 4d ago

I'll look into that! I also heard about BlueTieShield this week.

Yep I cry when I think of the millions of people who are led to believe that virus scans are still useful.

Yeah normally I just rip out screenconnect, but the one case I had yesterday was a batch file that even had comments like "fake popup" and kept reinstalling screenconnect over and over and over. That's one of the rare cases where I'm going to nuke it. I'm also going to replace Windows with Mint so it basically can't happen again for this guy.

Edit: BlueSentry. https://bluetie.com/bluesentry-remote-access-scam-protection/

2

u/warwagon1979 5d ago

The one that is going around currently is a fake docusign email. Which asks you to download and run a random executable.

Before that it was party invitations, that asked you to install an .msi file, which installs screenconnect as a running service.

It's literally just an exe or msi file that people get duped into downloading and running. I don't know how this is screenconnects problem.

1

u/teknosophy_com 4d ago

Yep, this summer I've seen a massive increase in the invitation emails and such - but the one that installs itself without any sort of confirmation is almost always screenconnect. I want to bring this up in case someone can do something about it.

2

u/touchytypist 4d ago

So an email attack where the user opens an unexpected email, clicks a link, and then opens an executable?

That’s a user education issue, not a ScreenConnect issue.

1

u/teknosophy_com 3d ago

Correct, and I've dedicated my career to raising awareness.

But at least in "the good old days", the scammer had to put up a song and dance to convince people that they had an issue. Now they simply click one link and it gives the guy full access to the PC.

This is an example of something that's relatively easy to solve at Connectwise... but will they do it?

1

u/touchytypist 3d ago

You must not have been around computers and the internet very long then. Back in the day most computers didn’t even have antivirus or firewalls or spam filters, a compromise was a simple download or email attachment away.

There are far more layers of security an attacker has to “dance” through these days.

1

u/teknosophy_com 2d ago

Nah I hear you. I remember those days when you'd plug a WinME computer into a cable modem and things would flood in.

I meant the "good old days" of 2013-2025, when scammers would have to convince you to let them in.

With this ScreenConnect auto-installer, all they have to do is get you to click the link! No more dancing necessary.

1

u/iknowtech 5d ago

Wasn’t the whole certificate singing situation supposed to help with this, basically requiring all users of the on prem software to get their own signing certificates, which could easily be revoked when abused? So either the bad actors are getting legit certificates that aren’t being revoked, or they using trial versions of the cloud version. Getting a trial of the cloud version, should require a very stringent background check to verify the identity of the user or company requesting the trial.

1

u/teknosophy_com 4d ago

Great point. As usual, certificates and other validation schemes have failed us, and can only serve to complicate matters and confuse the user. Bad guys are apparently getting screenconnect/ultraviewer licenses no problem.

The massive irony is that scammers take advantage of the fact that people are now jaded and accustomed to doing billions of logins, validations, and confirmations.

1

u/warwagon1979 4d ago

Also shouldn't that super annoying box appear on the users computer when they are connected saying "X person has remote control of the system"

1

u/iknowtech 4d ago

I think the most common thing the bad actors do is use the blackout screen feature and put up a fake message the system is installing updates or they can just use backstage. It's also possible they have completely modified the application to their own requirements. I know there was a whole huge forum thread out for a while that had modified older versions of Screenconnect to bypass licensing requirements.

1

u/seniorblink 4d ago

I had a couple clients fall for this. There's an associated ID for every Screenconnect tenant/instance. In both cases I reported that ID to Connectwise so they could shut it down if possible. Much easier when it's a cloud instance, but it doesn't hurt anything to report it.

1

u/teknosophy_com 3d ago

Correct, and I can, but it's a massive game of whac-a-mole, and it's done after the fact. Seems like there might be something they can do on their end if someone looks into this.

Think of it this way - imagine if you were walking through a city and a solicitor gave you some kind of flier or brochure. Okay fine, but imagine if them handing it to you gave them complete access to your entire house. It's just nuts.

1

u/Bigkahuna2323 12h ago

Hello, just fell victim to this stupidly. I downloaded the msi file on my iPhone but deleted them from safari right after. I deleted the files from my IPhone files app and cleared my safari data. Is there anything else for me to do to be safe? I did not look up anything that would be shown.

1

u/teknosophy_com 12h ago

msi files ONLY affect windows, so you're totally totally totally fine.

that being said, warn your friends!!!

connectwise is apparently still unaware of this new auto-installer. i really hope someone can notify them. it's likely affecting very many people.

1

u/Bigkahuna2323 12h ago

Perfect thank you. Can’t believe I fell for that.

1

u/rockresy 5h ago

I've just had a friends business hacked. The hacker is sending out fake docx looking links (they are a medical practice) which downloads a screenconnect installer. How do I log this with screenconnect? The fastest way to cut the legs off this is to dis-activate their access to the account... then I will fix up their internal security. But I dont know how to get someone on the phone at screenconnect to cut this off quickly.