ConnectWise

Malware

⚠️ Overview

ConnectWise is a family of remote access trojans (RATs) and backdoors that abuse legitimate ConnectWise remote management software, particularly ScreenConnect (now ConnectWise Control), for malicious purposes. First documented in widespread campaigns around 2020 by cybersecurity firm Huntress, this malware category includes custom payloads that piggyback on trusted ConnectWise tools to achieve initial access and persistence. It is typically deployed by ransomware groups such as LockBit and Black Basta, and classified as a living-off-the-land binary (LOLBIN) attack vector.

🔧 Technical Capabilities

The primary attack vector involves phishing emails or compromised credentials that allow threat actors to install ConnectWise Control’s legitimate remote access agent on target machines. Once installed, adversaries use the agent’s built-in features to execute arbitrary commands, upload additional tools (e.g., Cobalt Strike, Mimikatz), and maintain persistent remote access without triggering traditional security alarms. Evasion techniques include abusing trusted digital signatures from ConnectWise, using encrypted C2 communication over standard HTTPS ports (443), and employing process injection into legitimate processes like ScreenConnect.WindowsClient.exe. Persistence is achieved by configuring the agent as a Windows service or scheduled task, allowing reconnection even after reboots. The malware does not require custom C2 infrastructure; instead, it uses the attacker-controlled ConnectWise server infrastructure, making network detection difficult. MITRE ATT&CK techniques include T1219 (Remote Access Software) and T1071.001 (Application Layer Protocol: Web Protocols).

📜 History & Notable Incidents

Major incidents involving ConnectWise-malware families include the 2023 attack on MGM Resorts, where Scattered Spider used ConnectWise ScreenConnect to maintain access. A critical vulnerability, CVE-2024-1709 (CVSS 10.0), was disclosed in February 2024 affecting ConnectWise ScreenConnect 23.9.7 and earlier, allowing remote code execution and authentication bypass. This vulnerability was actively exploited by ransomware groups within days of disclosure. Law enforcement actions include the FBI’s 2024 warning about threat actors abusing legitimate remote monitoring tools, including ConnectWise.

🔍 Detection Indicators

Indicators of compromise include unexpected installations of ConnectWise Control clients on non-IT systems, outbound connections to attacker-controlled ScreenConnect servers (e.g., IP addresses associated with Shadow IT or unknown hosting providers), and file hashes of malicious payloads such as ScreenConnect.ClientService.exe with non-standard digital signatures. Behavioral indicators include the agent running under unusual user accounts or executing command-line tools like powershell -enc. Registry keys under HKLMSoftwareScreenConnect or named pipes related to ScreenConnect sessions may be present. User-Agent strings can be spoofed but often match default ConnectWise agent identifiers.

☠️ Risk & Impact

The impact of ConnectWise-malware attacks includes full network compromise, data exfiltration, and ransomware deployment. Affected sectors span healthcare (e.g., 2024 attack on Change Healthcare), education, and managed service providers (MSPs), where attackers pivot from MSP tools to client networks. Financial losses from ransomware incidents involving ConnectWise have exceeded tens of millions of dollars collectively.

🛡️ Mitigation

Mitigation strategies include applying vendor patches for CVE-2024-1709 immediately, restricting ConnectWise Control access to approved IP ranges, and enabling multi-factor authentication (MFA) on remote access accounts. Detection rules should monitor for non-standard ScreenConnect installations and block outbound connections to unknown ScreenConnect servers. Use endpoint detection and response (EDR) tools with behavioral rules for LOLBIN abuse.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.