Back Isc.Sans.Edu ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
I received a very simple phishing email:
This email passed all the basic security controls. The link points to a real PE file. Today this attack vector will be blocked by browsers because downloaded an executable is suspicious!
The PE file was unknown on VT so I did a quick analysis of it. It’s a legit application: a ScreenConnect[ 1 ] client preconfigured to call-back a test account operated by the Attacker. Here is the configuration extracted from the PE file:
instance-v2e3e2-relay.screenconnect.com
v2e3e2 (ConnectWise-hosted cloud)
RSA-2048 public key, blob SHA256 16b1cec1…9b00ead7
The PE is signed by ConnectWise, LLC (DigiCert G4 Code Signing CA1). The Authenticode digest matches the signed digest exactly. There's no overlay and nothing appended to or injected into the certificate table, so the signed-but-tampered config trick isn't used here.
Such tools are a gold mine for attackers because they are easy to deploy and trusted by most used! The list of “RMM” (Remote Monitoring and Management) tools is huge. Here is a brief list of the well-known ones;
Bomgar (BeyondTrust Remote Support)
Remote utilities like rutserv.exe
If you want a better overview, check LOLRMM project [ 2 ] that maintains a list similar to the LOLBAS project!
[1] [2]
Xavier Mertens (@xme) Senior ISC Handler | SANS Principal Instructor | Freelance Consultant Xameco | PGP Key
Login here to join the discussion.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
