Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client's Authenticode signature. ConnectWise ScreenConnect is a remote monitoring and management (RMM) software that allows IT admins and managed service providers (MSPs) to troubleshoot devices remotely. When a ScreenConnect installer is built, it can be customized to include the remote server the client should connect to, what text is shown in the dialog boxes, and logos that should be displayed. This configuration data is saved within the file's authenticode signature. This technique, called authenticode stuffing, allows for the insertion of data into a certificate table while keeping the digital signature intact. Cybersecurity firm G DATA observed malicious ConnectWise binaries with identical hash values across all file sections except for the certificate table. The only difference was a modified certificate table containing new malicious configuration information while still allowing the file to remain signed. G DATA says the first samples were found in the BleepingComputer forums, where members reported being infected after falling for phishing attacks. Similar attacks were reported on Reddit. These phishing attacks utilized either PDFs or intermediary Canva pages that linked to executables hosted on Cloudflare's R2 servers (r2.dev). The file, called "Request for Proposal.exe," seen by BleepingComputer, is a malicious ScreenCo...
Hackers turn ScreenConnect into malware using Authenticode stuffing
BleepingComputer
·Lawrence Abrams
·Published Jun 25, 2025
·Updated
Affected Software
1 affected component
ConnectWise ScreenConnect
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how hackers are exploiting ConnectWise ScreenConnect to create signed remote access malware using Authenticode stuffing.
2
What security implications are discussed?
The article highlights the risk of trusted software being compromised, leading to unauthorized remote access and potential data breaches.
3
What products or software are affected?
The primary software affected is ConnectWise ScreenConnect, which is used for remote monitoring and access.
4
How are hackers utilizing the Authenticode signature?
Hackers are modifying hidden settings within the Authenticode signature of the ScreenConnect installer to disguise their malware.
5
What is the purpose of the described attack?
The purpose of the attack is to create a legitimate-looking remote access tool that can be used for malicious activities without detection.