216.73.216.226

ScreenConnect Attack: SmartScreen Bypass and RMM Abuse

· Published 12/02/2026 10:39 · Modified 12/02/2026 21:53

Export JSON

Essential information

Published
12/02/2026 10:39
Modified
12/02/2026 21:53
Tags
2026-02-12 phishing privilege-escalation remote access trojan rmm abuse screenconnect smartscreen bypass social engineering uac bypass
Related entities
1 observables, 7 others

Description

An attack campaign targeting organizations in the US, Canada, UK, and Northern Ireland exploits ConnectWise vulnerabilities. The attack chain begins with a spoofed email containing a malicious .cmd attachment, which executes silently, escalates privileges, disables Windows SmartScreen, and removes the Mark-of-the-Web. It then installs a legitimate Remote Monitoring and Management tool, , which is abused as a for persistent command-and-control access. The campaign focuses on sectors with high-value data, including government, healthcare, and logistics. The attackers use various techniques to evade detection, including , registry modification, and silent MSI installation. The client used has a revoked certificate, highlighting the importance of blocking vulnerable software versions and enforcing strict RMM allowlists.

External references