Attackers Abuse ScreenConnect Remote Support Client to Pivot into Victim Networks
What Happened — Threat actors are leveraging the ScreenConnect (now ConnectWise Control) client to obtain remote access to target systems. In several observed cases the legitimate client was installed on victim machines, then abused—either through stolen credentials or by exploiting weak configuration—to move laterally and exfiltrate data.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of third‑party remote‑access tools is essential; without it, a benign‑looking client can become a covert foothold.
- Demonstrable evidence that remote‑access applications are inventoried, hardened, and their usage logged satisfies a core control objective around vendor‑supplied software oversight.
- The incident underscores the need for an auditable process that validates that only authorized users can launch remote sessions, aligning with a control‑assurance program’s requirement for defensible access logs.
Who Is Affected — Enterprises across all sectors that deploy remote‑support solutions, especially technology services, managed service providers, and internal IT teams.
Recommended Actions
- Inventory all ScreenConnect (ConnectWise Control) installations and verify they are authorized.
- Enforce MFA and least‑privilege for any accounts that can launch remote sessions.
- Enable detailed session logging and integrate logs into a centralized SIEM for continuous review.
- Conduct a rapid configuration audit against your remote‑access control policy and remediate any gaps.
Technical Notes — The abuse does not rely on a new CVE; instead, attackers exploit default credentials, weak password policies, or misconfigured firewall rules that allow inbound remote‑control traffic. The primary data at risk includes internal credentials, proprietary files, and any data accessed during the remote session. Source: SANS Internet Storm Center