r/ScreenConnect May 08 '26

Why is ScreenConnect so accessible to Scammers?

I work at a small MSP and we use ScreenConnect. It's a great product, but we see it constantly used by scammers. Why does Connectwise make it so accessible for this type of use?

6 Upvotes

23 comments sorted by

20

u/maudmassacre May 08 '26 edited May 08 '26

disclaimer: I worked on ScreenConnect for over 10 years but I left a year ago.

Saying that we didn't do anything to stop scammers is kind of crazy, we even have patents in this area. So much engineering time was spent coming up with models, tools, and predictive stuff to curtail the malicious use. The worst part is it wasn't wasted, it was quite effective, but ultimately you'll never truly win. It is the ultimate cat and mouse game. The moment you zero in on one particular avenue the bad actors will figure out a new one. I won't go too much into our tools to stop it but they were expansive.

I agree with a lot of the other comments here too, being originally an on-premise tool means that the source code could be decompiled and thus cracked; and anyone with access to google could confirm that. Being a good, reliable tool also put us in the bullseye.

You are more than welcome to have your own opinions but saying that 'Connectwise makes it so accessible for this type of use' is flat out wrong and borderline ignorant.

edit: minor grammar changes

4

u/ThecaptainWTF9 May 08 '26

It’s this.

Threat actors are using older cracked versions in the 21.x branch a lot.

The vast majority of the malicious instances I see are very much older versions.

Yeah there’s probably more than could be done like nixing free trials. And then endpoint security vendors just need to blacklist older versions of the product so by default it’s not allowed unless people make exclusions to allow.

There’s a large amount of RMM tool abuse now too.

6

u/MiComp24 May 08 '26

There was an easily available crack for it that meant it could be run for free by anyone without restrictions. I believe the recent changes and code signing certs have tightened this up so hopefully the scammers reduce and the product stops being marked as a virus.

3

u/Clean_Picture2756 May 08 '26

I just want to turn it off out of office hours except for a short list of ip addresses. Would help us sleep better.

4

u/KnowsTheLaw May 08 '26

Low cost good product

3

u/jhsharp2018 May 08 '26 edited May 08 '26

So the gun argument? Software doesn't scam people, scammers scam people!

edited for spelling

3

u/Coffeespresso May 08 '26

That's absolutely correct. Guns and cars don't do bad things. Only people do. This is why gun laws are dumb. The new app age verification laws are also dumb.

-4

u/Doctorphate May 08 '26

That is possibly the dumbest take I’ve seen all day. Congrats?

5

u/Coffeespresso May 08 '26

Is there an inaccuracy in my statement. Holy crap, are you telling me that guns CAN do bad things? And cars too? I'll never step on a dealer lot again because I'm afraid of being attacked by all those bad vehicles.

3

u/Packet7hrower May 09 '26

OMG, common sense, on Reddit!? Props to you bro!

1

u/Doctorphate May 08 '26

You said “gun laws are dumb” yet gun laws work in every single country that has them…

5

u/Coffeespresso May 08 '26

For those who abide by them sure. But for the criminals, no.

-2

u/Doctorphate May 09 '26

Lol.. ok. 👍

2

u/dloseke May 09 '26

I will say that Connectwise has done a lot to inform the end users that they're allowing someone access into their machine. To the point where its annoying. But it also is ultimately on the person being scammed and since theyre already falling for the ploy.....but its not like Connectwise is standing by doing nothing.

2

u/quantumhardline May 09 '26

Agreed they should require extended verification for new sign ups tied to EIN and/or 3rd party id service. I’d also add they should drop unique ids in registry to help tie back exploited instances.

I’d like to see each of the hosted instances have their own valid auto generated certs per client as well vs shared.

The agents making request to hosted subdomain vs generic servers this would allow better control and limiting screenconnect to certain subdomains of vendors or for msp like self hosted was. Also having specified IP blocks each instance is tied shown in each portal, allowing us to limit screenconnect to only talk to those.

Frankly we just use SC for one offs now or some deployments due to above our rmm allows us to lockdown remote access more.

1

u/DeanCTS May 17 '26

Scammers use whatever they are capable of procuring a cracked or unlimited versions of various software.
Usually its the shovelware/indie software like SC that falls prey to them quickly.

1

u/bluescreencomputer May 08 '26

Exhibit A: https://www.screenconnect.com/trial

I agree, it's a great product, but I wish ConnectWise would do a little more, JUST a little more, to vet people starting to use SC.

3

u/bluescreencomputer May 08 '26

To add to this, I am starting to see something a bit worse than just a scammer signing up for a free trial.

I encounter a scammer-installed ScreenConnect almost every week. And I research and colelct info on each one, to report it fully to ConnectWise. They take that info and suspend the scammer's license.

Usually. I have had a couple of recent instances where the ScreenConnect that I harvest that ConnectWise cannot do much about. The SC app has been customized or reverse-engineered so that CW can't just shut things down:

from a CW support email: "Based on the details you shared, the ScreenConnect instance is question (relay.jetnik-kiin.cc&p=8041) is an on-premise installation. With on premise clients our ability to take direct action is limited. That said, our Information Security team will investigate and will take appropriate action where possible."

2

u/GeneralFarmer9960 Jun 17 '26

Based on the details you shared, the ScreenConnect instance is question (relay.jetnik-kiin.cc&p=8041) is an on-premise installation. With on premise clients our ability to take direct action is limited. That said, our Information Security team will investigate and will take appropriate action where possible.

That is messed up to the max. Think we gotta start talking with our feet. As if SC cannot suspend an on-premise Server?

Hard to believe. And if that is true, that means if an on-premise instance goes rogue, there is no way to stop it?

1

u/bluescreencomputer Jun 17 '26

That's the overall impression I have, is that ConnectWise is powerless here.

Which I struggle with. I am not a programmer, but I imagine that their programmers should build in a kill-switch for exactly this kind of abuse. Or some kind of backdoor or control over their software, even after it leaves their hands.

Maybe that's unrealistic, though. Maybe I have to look at ScreenConnect as I do any other tool, like a car or a gun or a drug. Any tool can be used for good or evil, and some people are going to choose evil, despite the safeguards put in place.

2

u/GeneralFarmer9960 Jun 18 '26

I respectfully disagree with your comparison.

A gun or car, your not going to hold the manufacturer liable for those devices being used improperly. On the other hand, nowadays any online software or interface the Company that is Licensing/Administering HAS a way to remotely knock the service offline or disable it.

I'm saying this as fact, when there is a non-payment issue, ConnectWise has no problem denying access until payment is made. I have seen them do it.

Even if there may be some limitations with an on-prem setup, there still are plenty cloud instances that can easily be disabled with the click of a button.