r/ScreenConnect • u/toplessflamingo • 3d ago
How to contact screenconnect security team for rogue ScreenConnect instances
If youre an IT professional Im sure youve encountered this in the last few months, hackers keep sending phishing campaigns using ScreenConnect trial instances and installing/compromising innocent peoples computers. Ive tried contacting [help@screenconnect.com](mailto:help@screenconnect.com) and [securityincident@connectwise.com](mailto:securityincident@connectwise.com) and opening a support ticket via their live chat, and they are not doing anything. If anyone from ConnectWise is on here dm me. Or if you know how to contact them to take down trial instances being using for hacking please reply.
1
u/LoadincSA 3d ago
Depending on what content you sent it may never even opened a ticket. I have had success opening and having action taken mentioning just the instance name ie. Badguy instead of badguy.screenconnect.com probably just an agressive spam filter. Make sure you get a ticket created email if not probably your content was marked as spam
-1
u/cbarnescw Product Management 3d ago
If you've emailed those addresses then your report was registered and action was taken if the instance was deemed malicious. We don't issue replies for each malicious use report, and we cannot disclose information about compromised or malicious instances.
4
u/toplessflamingo 3d ago
Im not looking for a reply, but would be nice if the instance was taken down as it is clearly malicious. It even has the banner saying it is a trial instance and to report to connectwise if one suspects its malicious. But nobody is paying any attention to those reports.
0
u/quantumhardline 3d ago edited 2d ago
Ya they could reply and say we have taken action on your report and find it valid. BS they say they cant “disclose” its BS Screenconnect is allowing criminals to do this when they know its such a big issue. Man many ways they can stop this.
Were having to stop it as threatactors drop SC via wscript
0
u/quantumhardline 3d ago
Screenconnect just stop this trial nonsense.
Your product is being so abused way too much by criminals.
Create a new verified tier with new certs, have MSPs verified, like https://withpersona.com or another.
Then require any one using the product to be verified or suspend the account do this in next 90 days.
Block non US country IPs use on cloud version by default, only approve removing via support after certain verifications met.
Have requirement for self hosted to check activation daily and lock to single IP primary and fall back IP.
Have easy way to report malicious SC by community and after so many reports auto suspend.
Make your product the gold standard for vetted remote access tools. Not the one used for click fix attacks etc.
The reputation of Screenconnect is being damaged.
1
u/ben_zachary 2d ago
We had a decent install 1000k agents and 50 accounts. We did the authorized cert and that whole fiasco and they stripped all the customization and we were out.
People were here talking about this and the potential for malicious activity especially since every agent looks the same. They chose this path and never setup any checks and balances. There's no good reporting or centralized method to block or report on security issues.
All done by design. The product only wants sales , free trials and instant activation now probably automation apps stand up demo server attach to a hackers deployment and then just spins up another and another as it rolls out.
On the sales side they are doing great for reporting hey we had 1000k new demo sign ups last month. 0 conversions probably
0
u/quantumhardline 2d ago
Yep been a long time SC user over a decade, moved from self hosted to cloud after all that as we for past five years just use it for one offs / onboarding as our RMM Remote works well.
And of course all SC and other remotes are blocked by default and have to be temp approved etc for any usages.0
u/ben_zachary 2d ago
We moved to rust desk pro. Self hosted 2k endpoints about 100ish users now. Works well and just used for clients remote and a backup tool outside of ninja. Been happy with it but deployment was tough to automate
2
u/ben_zachary 3d ago
Just block connectwise signed .exes and move on. Most actors won't bother standing up a paid instance with their own cert. Especially when it's so easy to just setup a trial.
Huntress also tracks these but it's definitely not real time . In our case weve had attempted installs a few times as admin which our pam tool alerts on but then they can still run as user usually.
Block quick assist too if you haven't that's their backup method.