Hackers are increasingly modifying legitimate ConnectWise remote access applications to hide malware and compromise systems, G Data warns .
See also: ConnectWise changes code signing certificates

While investigating multiple incidents of malware infections originating from ConnectWise customers, G Data identified the use of the “Authenticode stuffing” technique, which allows legitimate software to be modified to install malicious code, bypassing security systems.
Authenticode digital signing is a technique that allows developers to verify the integrity of a file. However, ConnectWise uses a workaround to avoid re-signing files when creating custom installers, which opens the door to abuse.
Specifically, this bypass relies on storing configuration data in the certificate table, and attackers use the same method to hide malicious code in the table.
This technique, known as “Authenticode stuffing,” has been used in a malicious campaign called EvilConwi, which distributes malware through modified ConnectWise clients that appear to pass integrity and authenticity checks.
See also: CISA: ConnectWise ScreenConnect vulnerability in the KEV Catalog
Because malicious settings and payloads are embedded in the configuration table, Windows does not verify their hashes, and modified installers do not invalidate the valid digital signature.

Since March 2025, G Data has observed an increase in the misuse of ConnectWise to install malware. When analyzing a modified version of the application, it was revealed that attackers used the Authenticode stuffing technique not only to hide the malicious code, but also to completely hide the installation of the ConnectWise client on the system.
The modified software falsely presents itself as an AI-to-image converter and disables various visual indicators that would alert the user to the presence of ConnectWise. It also simulates a Windows update, displaying an update screen image and prompting the user to keep the system connected to the internet. It also displays misleading messages and window titles, intended to hide the fact that attackers have remote access to the infected system.
See also: ConnectWise: State hackers behind the cyberattack?
The security firm notified ConnectWise of the observed malware installations on June 12 and noted that the company revoked the signature of the observed samples on June 17.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
