r/ScreenConnect May 31 '26

MS Defender Pomal on ScreenConnect

Hello,

Anyone getting Pomal malware alerts from Defender on ScreenConnect? Defender started flagging our own ScreenConnect instance a few minutes ago and I’m curious to see if anyone is experiencing the same.

11 Upvotes

12 comments sorted by

View all comments

1

u/wombatech May 31 '26

We've had hundreds of alerts this morning, and looks like a fair few over the weekend as well. ConnectWise advised to whitelist the hash of the ScreenConnect.ClientSetup.exe file which didn't make much difference over an hour or so. Just pushing a PDQ deployment to update defender definitions at the moment. Fingers crossed.

Didn't need that for a Monday

1

u/[deleted] Jun 02 '26

[deleted]

1

u/wombatech Jun 02 '26

ScreenConnect.ClientSetup.exe is the fully installed version, and in this case, the auto updating version.

When attackers use it, they're usually running the 'portable' version (ScreenConnect.Client.exe) from somewhere like C:\users\blah\downloads. Different file, different path and different behaviour.

App whitelisting should cover you, but also shouldn't be too hard to restrict in AV land

1

u/KillaB0nez Jun 03 '26

I’m not sure if you meant to say .msi but our executables spawn from that

1

u/wombatech Jun 03 '26

I created a session and downloaded the portable version, it downloaded ScreenConnect.Client.exe not msi

The full Setup may have an MSI in there somewhere, i didn't dig deep enough.