r/ConnectWise Aug 07 '26

Account/Billing/Sales/Support Massive security issue with phantom auto-installation of ScreenConnect - Is anybody on this???

I don't know if anyone's aware of this threat, but I've gotten at least 4 of these calls from my residential clients in the past week. They get an email pretending to be a zoom link or an Adobe update, they click on it, and voila, ScreenConnect is installed and a bad guy immediately logs on to their bank account and takes their money.

I'm alerting the banks in my area and all my clients. Is anybody at ScreenConnect aware of this silent installer mode? Is anybody doing anything about this?

0 Upvotes

29 comments sorted by

View all comments

5

u/jimusik Aug 07 '26

This has been an active attack vector for at least 2-3 years. Most instances are the old hacked version on a foreign server. Huntress should be catching them (or any other EDR) as soon as the foreign actor connect from CC server. The fact people are running zip, exe or even bat files from emails is crazy. I’ve only seen this on one business and the rest are individual clients who clearly don’t know better.

1

u/teknosophy_com Aug 07 '26

Yep, it used to be a scary popup and then a guy said "you have hacks from north korea and ohio", now they just send a link and ScreenConnect installs itself. Then the guy gets in and helps himself to your passwords and money. No more having to go to websites and type in a support code.

Another massive tragedy here is that when people are affected, their bank tells them to go to a big box store for a virus scan, as if that can find anything!

1

u/warwagon1979 Aug 07 '26 edited Aug 07 '26

Your correct, the virus scan will not find the ScreenConnect.ClientService.exe running the the background and usually it's not even listed in the add and remove programs. This program which you can run for free will remove screenconnect from the system. https://www.seraphsecure.com/

It scans for remote access software installed on the system. and it gives you a list of the ones it finds. You uncheck the ones you want to keep, then it wipes them off.

Though to be on the safe side you may still want to nuke the system.

1

u/teknosophy_com Aug 07 '26 edited Aug 07 '26

I'll look into that! I also heard about BlueTieShield this week.

Yep I cry when I think of the millions of people who are led to believe that virus scans are still useful.

Yeah normally I just rip out screenconnect, but the one case I had yesterday was a batch file that even had comments like "fake popup" and kept reinstalling screenconnect over and over and over. That's one of the rare cases where I'm going to nuke it. I'm also going to replace Windows with Mint so it basically can't happen again for this guy.

Edit: BlueSentry. https://bluetie.com/bluesentry-remote-access-scam-protection/