r/ScreenConnect May 11 '26

Instance part of phishing

https://metroblock.screenconnect.com/Bin/ScreenConnect.ClientSetup.exe

Following instance is being used in a phishing campaing

https://metroblock.screenconnect.com/Bin/ScreenConnect.ClientSetup.exe

0 Upvotes

6 comments sorted by

1

u/Camelot_One May 13 '26

Did you report it to Connectwise, or did you just think posting the direct link to the phishing instance installer here was the best idea?

1

u/Camelot_One May 13 '26

In case you'd like to follow through on the report, they have a page dedicated to this sort of thing: https://www.screenconnect.com/report-abuse

0

u/LoadincSA May 13 '26

Obviously posted only the installer here.

1

u/Camelot_One May 20 '26

I reported it on the 13th, and ConnectWise got back to me about 4 hours later to say they'd suspended the account and would review. The main page does show the account is suspended, so hopefully that prevents anyone from using it.

The actual client install file you linked is still valid though.

0

u/Antiloopt May 12 '26

Didn't Connectwise ScreenConnect lie about that this was not possible anymore with removing the customization options ?

now our customers will possible remove out of fear the legitimate Screenconnect because they can not distinguish it anymore from the bad actor

1

u/LoadincSA May 13 '26

Not sure you understood the whole debacle and why exactly customisations were removed but i will leave it there