Remote monitoring and management (RMM) tools have long been integral tools for IT administrators, providing seamless remote control, seamless access, and scripted automation to corporate endpoints, via ScreenConnect.
See also: ScreenConnect used to distribute RATs

In recent months, security researchers have observed an increase in attacks where malicious actors are reusing ScreenConnect—a ConnectWise RMM solution—as a hidden backdoor for initial intrusion and ongoing control.
Emerging from widespread phishing campaigns exploiting compromised credentials, these attacks leverage ScreenConnect's flexible installer and invitation mechanisms to bypass traditional defenses with a minimal disk footprint.
The campaign typically begins with spear-phishing emails that pretend to be legitimate IT notifications, enticing recipients to download a specially crafted ScreenConnect installer or click on an invitation link.
Once executed, the MSI package deploys entirely in memory, bypassing signature-based detection by antiviruses and leaving only a transient service binary.
The installed agent then registers as a Windows service, giving attackers unrestricted access to file systems, running processes, and the computer's network.
Within hours, hackers have been observed moving laterally, escalating privileges, and extracting sensitive data under the guise of routine maintenance.
See also: AsyncRAT exploits ConnectWise ScreenConnect

Dark Atlas analysts discovered that attackers are customizing builder configurations in real-time, embedding unique hostnames and encrypted startup keys directly into the client's system.config file to avoid network compromise indicators.
These dynamically generated parameters are mapped to an XML section of ScreenConnect.ApplicationSettings, where malicious domains are resolved to infrastructure controlled by the attackers.
This tactic not only obfuscates command and control channels but also ensures that each deployment appears as a separate operational instance to defenders. The ScreenConnect installer leverages built-in RMM capabilities to minimize detection while maintaining persistence.
Attackers create a custom builder from the management console, choosing an MSI or EXE packager depending on the target environment. When launched, the installer writes a WindowsClient and associated DLLs to a seemingly innocent directory—such as C:\ProgramData\ScreenConnectClient\—before invoking the service with a disguised command line.
After installation, the agent creates an XML system.config, storing attacker.example.com-203.0.113.45-1631789321000, connecting the client to its command server. Persistence is achieved through a registered Windows service named ScreenConnect ClientService, which restarts the binary on reboot.
See also: Hackers abuse ConnectWise to hide malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

By combining in-memory execution, custom builders, and encrypted launch keys, malicious actors turn a legitimate RMM solution into a silent remote access Trojan, complicating detection and incident response for security operations teams.
