• News/
  • https://www.bleepingcomputer.com/news/security/hackers-turn-screenconnect-into-malware-using-authenticode-stuffing/

Hackers turn ScreenConnect into malware using Authenticode stuffing

BleepingComputer
·
Lawrence Abrams
·
Published Jun 25, 2025
·
Updated

Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's  Authenticode signature. ConnectWise ScreenConnect is a remote monitoring and management (RMM) software that allows IT admins and managed service providers (MSPs) to troubleshoot devices remotely. When a ScreenConnect installer is built, it can be customized to include the remote server the client should connect to, what text is shown in the dialog boxes, and logos that should be displayed. This configuration data is saved within the file's authenticode signature. This technique, called authenticode stuffing, allows for the insertion of data into a certificate table while keeping the digital signature intact. Cybersecurity firm G DATA observed malicious ConnectWise binaries with identical hash values across all file sections except for the certificate table. The only difference was a modified certificate table containing new malicious configuration information while still allowing the file to remain signed. G DATA says the first samples were found in the BleepingComputer forums, where members reported being infected after falling for phishing attacks. Similar attacks were reported on Reddit. These phishing attacks utilized either PDFs or intermediary Canva pages that linked to executables hosted on Cloudflare's R2 servers (r2.dev). The file, called "Request for Proposal.exe," seen by BleepingComputer, is a malicious ScreenCo...

Read full article

Affected Software

1 affected component
ConnectWise ScreenConnect
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how hackers are exploiting ConnectWise ScreenConnect to create signed remote access malware using Authenticode stuffing.

2

What security implications are discussed?

The article highlights the risk of trusted software being compromised, leading to unauthorized remote access and potential data breaches.

3

What products or software are affected?

The primary software affected is ConnectWise ScreenConnect, which is used for remote monitoring and access.

4

How are hackers utilizing the Authenticode signature?

Hackers are modifying hidden settings within the Authenticode signature of the ScreenConnect installer to disguise their malware.

5

What is the purpose of the described attack?

The purpose of the attack is to create a legitimate-looking remote access tool that can be used for malicious activities without detection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203