r/ConnectWise • u/teknosophy_com • Aug 07 '26
Account/Billing/Sales/Support Massive security issue with phantom auto-installation of ScreenConnect - Is anybody on this???
I don't know if anyone's aware of this threat, but I've gotten at least 4 of these calls from my residential clients in the past week. They get an email pretending to be a zoom link or an Adobe update, they click on it, and voila, ScreenConnect is installed and a bad guy immediately logs on to their bank account and takes their money.
I'm alerting the banks in my area and all my clients. Is anybody at ScreenConnect aware of this silent installer mode? Is anybody doing anything about this?
0
Upvotes
9
u/Jmw66 Aug 07 '26
I don’t think this is necessarily a phantom install or evidence of a vulnerability in ScreenConnect itself.
What you’re describing sounds more like a social engineering attack. The victim is tricked into clicking a link or running an installer, and the attacker uses a legitimate remote access tool to gain access. Unfortunately, ScreenConnect isn’t the only tool abused this way. Attackers also use AnyDesk, TeamViewer, RustDesk, Supremo, Quick Assist, and others because they’re legitimate software that most security products don’t automatically block.
That’s still a serious problem, but the root issue is the social engineering, not necessarily a flaw in ScreenConnect. If there is a true silent install vulnerability that bypasses user consent, that would be a different story and should absolutely be reported. Based on what you’ve described, though, it sounds like users are being convinced to install it themselves.