Increased Abuse of ScreenConnect by Threat Actors in 2025
Article Content
Browse articles
In 2025, there has been a significant rise in the abuse of ScreenConnect and other remote monitoring and management (RMM) tools by threat actors. Organizations using outdated or unpatched versions of these tools are particularly affected, as highlighted by reports from both Huntress and Barracuda Networks. The Huntress 2025 Cyber Threat Report noted that 17.3% of all threat incidents involved compromised ScreenConnect installations.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track NetSupport, ConnectWise and CVE-2025-3935 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ClickFix Scam: Users Self-Install Malware via Social Engineering The ClickFix scam has emerged as a significant threat, tricking users into executing malicious PowerShell scripts under the guise of fixing technical issues. Threat actors, including TA571 and the ClearFake activity cluster, utilize social engineering tactics such as fake CAPTCHAs and browser error messages to prompt…
New ScreenConnect Flaw Enables Malware Spread via Rogue Clients ConnectWise has identified a critical vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments. The flaw, which impacts file transfer functionality, allows attackers to deploy rogue ScreenConnect clients that spread malware to connected systems. This malware is propagated through…