Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
A large-scale phishing campaign deploys unauthorized ConnectWise ScreenConnect clients by impersonating trusted application stores and software update mechanisms. The campaign uses sophisticated social engineering pages replicating Google Meet, Microsoft Store, and Apple App Store experiences, with AI-assisted victim profiling scripts exfiltrating telemetry via Telegram Bot API. Payloads are distributed through attacker-controlled infrastructure, Amazon S3, and Cloudflare R2, with batch files performing silent MSI installation via UAC bypass techniques.
- domainaspenbio[.]topU.S. Social Security Administration-themed phishing domain
- domainbestchoice[.]sa[.]comAttacker-controlled domain resolving to 69.49.246.105, used for DocuSign-themed phishing deployment
- domainbiohera[.]spaceInfrastructure correlated via smartpocketmoney.com reverse DNS
- domainbotdip[.]cloudDocument Review-themed phishing domain
- domainchecklist-event[.]comHoneypot redirect domain used in anti-automation controls to divert automated scanners away from payload delivery
- domaincloudhudson[.]cloudDocument Review-themed phishing domain
- domaincloudyspoon[.]storePUNCHBOWL Electronic Card Invitation-themed phishing domain
- domaincryptora[.]pwAdobe Acrobat / Blue Mountain-themed phishing domain
- domainebrobot[.]cloudInfrastructure correlated via smartpocketmoney.com reverse DNS
- domainecoprune[.]siteDocument Review-themed phishing domain
- domainislund[.]siteAdobe Acrobat / Blue Mountain-themed phishing domain
- domainjceic[.]topAdobe Acrobat / Blue Mountain-themed phishing domain
- domainjumpingcloud[.]topSecure Document Portal-themed phishing domain
- domainloanix[.]clubAdobe Acrobat-themed phishing domain
- domainpaperorbit[.]cloudDocuSign-themed phishing domain
- domainpaperwhale[.]cloudMS Teams Transcript-themed phishing domain
- domainpaylad[.]onlinePUNCHBOWL Electronic Card Invitation-themed phishing domain
- domainpaypig[.]onlinePUNCHBOWL Electronic Card Invitation-themed phishing domain
- domainpixelio[.]siteSecure Document Portal-themed phishing domain
- domainrenewfog[.]spaceInfrastructure correlated via smartpocketmoney.com reverse DNS
- domainseoulapp[.]techMS Teams Transcript-themed phishing domain
- domainsmartpocketmoney[.]comReverse DNS namespace for attacker infrastructure; name servers ns1/ns2.smartpocketmoney.com used to correlate additional campaign domains
- domainsoapano[.]siteAdobe Acrobat / Blue Mountain-themed phishing domain
- domainstcdubai[.]comPrimary phishing domain hosting fake Google Meet pre-join experience and ScreenConnect payload delivery
- domaintabearl[.]cloudInfrastructure correlated via smartpocketmoney.com reverse DNS
- domaintalent[.]qponAdobe Acrobat / Blue Mountain-themed phishing domain
- domaintonora[.]cloudAdobe Acrobat / Blue Mountain-themed phishing domain
- domainurbanio[.]onlineAdobe Acrobat-themed phishing domain
- domainyellowrabbit[.]sitePUNCHBOWL Electronic Card Invitation-themed phishing domain
- ip69[.]49[.]246[.]105Attacker-controlled server (AS19871) hosting phishing frameworks and directly controlled by operator, unlike compromised sites elsewhere in campaign
- sha256246ec497890d94776ccf6bfb14bd5a3568cde115b72926527841255fa0a44aa7Hash of FileDOC0626-14.bat batch file
- sha256415da0881ae2019a096bba596c1643fee0ec44d08682f748f88a39665d99a375Hash of InviteJuly26.bat / Q12 2026 SETTLEMENT.bat batch file
- sha256424ebbbec7a6498badfe12e973247252ee4f5f789c3f2007e716ec745a3cc55bHash of Q10-2026SETTLEMENT.bat batch file
- sha2565b6cff6946771502aab7f60038ff20b7e45d19ef5c5ed95b4ff0b8193ca4b75aHash of 2026Q1SETTLEMENT.bat batch file
- sha2567ad5b98d8790fe81408708df0ff2c607eea50021e9864942d66a297ea90c2c31SHA256 hash of ScreenConnect installer delivered by the campaign
- sha2567f8907a05b737e1b4ddedfe870cb99c0352a2cd8373671c26854d9711b88849bHTTP resource hash of static campaign resource reused across ~70 phishing frameworks
- sha2567fd3d2956d216c23e560f747d2ea30fb469986fac634ddc483e38bcca49bdd95HTTP resource hash of JavaScript redirect response body (window.location=' Windows/'), reused across ~590 phishing frameworks for platform selection
- sha2569cc0dfa491f5eebdca6a351e699886946b0b96fdbcb7d454ea15af2fffdf6b93HTTP resource hash of static campaign resource reused across ~1.7k phishing frameworks
- sha2569e6875670e605367ad86dfb62b0a42714129c2e83da49e43674a1beb4ada9867Hash of InvitedBlue26.bat batch file
- sha256bc9bcb5915fdc314ed0b3de952c83b3380048c4ffd1bc3579b7e1badd7fa9181SHA256 hash of INVOICE2515.bat / ViewDoc271.bat batch file that performs UAC bypass and silent MSI installation
- sha256c71ddfa376b2a86bae93d46d997742502d127979a8774402c936ec6832bb91d0Hash of QUOTE 36C.bat / Q4 2026 SETTLEMENT.bat batch file
- sha256d30d6a29859de6ff8232e346a044322cc53a02bca1d78bdaa8edde74def982dbHTTP resource hash of static campaign resource reused across ~120 phishing frameworks
- urlhxxps://baigetrc[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://bieagtdk[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://btegiacmq[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://ea-bnitkmg[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://eobtdk[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer for silent deployment
- urlhxxps://ieabgtsk[.]s3[.]us-east-1[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://kilodz[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://prjtmna[.]s3[.]us-east-1[.]amazonaws[.]com/ScreenConnect[.]ClientSetup[.]msiAWS S3 bucket hosting ScreenConnect MSI installer
- urlhxxps://pub-39190877e0004c3a84a95c22db10d23b[.]r2[.]dev/Secure_Document_Viewer[.]msiCloudflare R2 hosted ScreenConnect MSI disguised as Secure Document Viewer
- urlhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/1907797257/20260621_150522_cb1eadfc[.]msiCloudflare R2 hosted ScreenConnect MSI installer
- urlhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/1907797257/20260626_181121_3cf54548[.]msiCloudflare R2 hosted ScreenConnect MSI installer
- urlhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/6707110503/20260708_184219_e1bdbdc9[.]msiCloudflare R2 hosted ScreenConnect MSI installer
- urlhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/8405320297/20260630_154034_69eb5426[.]msiCloudflare R2 hosted ScreenConnect MSI installer
- urlhxxps://pub-d7ab35315be7454889d8f97c69fc2074[.]r2[.]dev/SSA_STATEMENT_EN_US[.]zipCloudflare R2 hosted ZIP archive containing ScreenConnect installer disguised as SSA statement
- urlhxxps://stcdubai[.]com/googlemeet/Fake Google Meet phishing page initiating the update social engineering chain
Detection / Hunteropenrouter
What Happened
Attackers are sending people to fake websites that look like Google Meet, the Microsoft Store, or the Apple App Store. These fake pages show convincing software update messages that trick victims into installing a remote access program called ConnectWise ScreenConnect. Once installed, the program automatically connects back to the attackers, giving them full remote control of the victim's computer. The attackers also use automated scripts to collect detailed information about each victim—including their IP address, location, browser, and operating system—and send this data to themselves through Telegram messaging. The malicious software is hosted on various cloud services including Amazon S3 and Cloudflare to evade detection. Anyone who uses a Windows computer and clicks on links from unexpected meeting invitations, document signing requests, or software update notifications could be affected. Organizations should check their computers for unauthorized ScreenConnect installations, train employees to be suspicious of unexpected software update prompts, and block access to known phishing domains.
Key Takeaways
- Large-scale phishing campaign impersonating Microsoft Store, Apple App Store, Google Meet, Zoom, Docusign, and other trusted apps to deliver unauthorized ConnectWise ScreenConnect clients
- Campaign uses AI-assisted scripts for victim profiling and exfiltrates telemetry via Telegram Bot API with hard-coded bot tokens
- Payload delivered via attacker-controlled infrastructure, Amazon S3 buckets, and Cloudflare R2 object storage with consistent directory structures and HTTP resource hashes enabling infrastructure pivoting
- Batch files use UAC bypass via Windows RunAs verb and hidden PowerShell windows to silently install ScreenConnect MSI packages
- Rogue ScreenConnect instances use pattern instance-XXXXXX-relay.screenconnect.com with y=Guest role, characteristic of free/trial cloud instances
Affected Systems
- Windows desktop systems (primary target)
- ConnectWise ScreenConnect clients
- Systems with msiexec.exe and PowerShell available
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim visits phishing page impersonating Google Meet, Microsoft Store, Apple App Store, or document-sharing platform
- Social Engineering: Page replicates trusted app UI, requests camera/mic permissions, then displays fake update modal redirecting to update.html
- Execution: update.html silently downloads ScreenConnect installer via hidden iframe, or batch file (.bat) is served with document-themed filename
- Privilege Escalation: Batch file uses PowerShell with RunAs verb for UAC bypass, executes in hidden window with elevated privileges
- Ingress Tool Transfer: Elevated PowerShell decodes ASCII-encoded URL and downloads ScreenConnect MSI from attacker-controlled host, AWS S3, or Cloudflare R2
- Persistence & C2: MSI installed silently via msiexec; ScreenConnect client auto-registers with attacker-controlled relay instance (instance-XXXXXX-relay.screenconnect.com) providing persistent remote access
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No formal detection rules are provided in the article. However, the article identifies HTTP resource hashes, recurring directory structures, reverse DNS artifacts, and Telegram bot tokens that can be incorporated into custom detection content.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | High | EDR should capture msiexec.exe silent installation, PowerShell hidden execution with ExecutionPolicy Bypass, UAC bypass via RunAs verb, and ScreenConnect client process creation with relay hostname command-line arguments. |
| Network Visibility | Medium | Network monitoring can detect downloads from S3 and Cloudflare R2 endpoints, communication with Telegram Bot API, and connections to instance-XXXXXX-relay.screenconnect.com relay patterns. However, HTTPS encryption limits payload inspection. |
| Detection Difficulty | Moderate | The campaign abuses legitimate RMM software and cloud storage services, making blanket blocking impractical. However, the consistent relay hostname pattern, HTTP resource hashes, and Telegram API calls provide reliable detection pivots. Anti-automation controls in the phishing pages may evade some automated scanners. |
Required Log Sources
- Process creation events (Sysmon Event ID 1 / EDR)
- Network connection events (Sysmon Event ID 3)
- PowerShell script block logging (Event ID 4104)
- DNS resolution logs
- Web proxy logs
- HTTP response body hashing capability
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for ScreenConnect client processes with command-line arguments containing y=Guest and relay hostnames matching the pattern instance-*-relay.screenconnect.com, which indicate rogue trial/free instance registrations | Process creation events with command-line logging | Command and Control | Low — legitimate enterprise ScreenConnect deployments use named instances and elevated roles, not Guest role on trial instances |
| Hunt for msiexec.exe processes executing with /quiet /qn /norestart flags where the MSI source path is in a temporary directory or user Downloads folder, preceded by a PowerShell process with hidden window style | Process creation events with command-line logging and parent-child process relationships | Execution | Medium — legitimate software deployments may use silent MSI installation, but the combination with hidden PowerShell and temp directory sourcing is suspicious |
| Hunt for network connections to api.telegram.org from endpoints that do not have a legitimate business requirement for Telegram communication, especially coinciding with web browsing activity | Network connection logs, DNS logs, proxy logs | Command and Control | Medium — some users may legitimately use Telegram; correlate with other indicators such as preceding downloads from S3 or R2 storage |
| Hunt for HTTP response bodies matching the known resource hashes (7fd3d2956d..., 9cc0dfa4..., d30d6a29..., 7f8907a0...) to identify additional phishing infrastructure using the same campaign framework | Web proxy logs with response body hashing, IDS/IPS with custom content matching | Resource Development | Low — these are specific JavaScript redirect response bodies reused across the campaign; legitimate use is unlikely |
| Hunt for batch files with document-themed names (INVOICE*.bat, ViewDoc*.bat, Invite*.bat, FileDOC*.bat) executing PowerShell with RunAs verb for UAC elevation in hidden windows | Process creation events, file creation events in temp directories | Execution | Low — batch files with invoice/document themes requesting UAC elevation via hidden PowerShell is highly suspicious |
Control Gaps
- Traditional URL filtering may not block Cloudflare R2 and AWS S3 endpoints as they are legitimate cloud storage services
- Application allowlisting may not flag ConnectWise ScreenConnect as malicious since it is legitimate RMM software
- Anti-automation controls in phishing pages (honeypot fields, time-based checks) may evade automated URL scanners and sandbox analysis
- HTTPS encryption prevents inline inspection of downloaded MSI payloads from cloud storage endpoints
- Blank index.php files suppress directory listings, making open-directory reconnaissance harder without knowing exact paths
Key Behavioral Indicators
- ScreenConnect client process with command line containing y=Guest and h=instance-*-relay.screenconnect.com pattern
- msiexec.exe with /quiet /qn /norestart flags installing MSI from temp or Downloads directory
- PowerShell process with -WindowStyle Hidden -ExecutionPolicy Bypass spawning cmd.exe with -Verb RunAs
- Batch file execution followed by PowerShell downloading MSI via Invoke-WebRequest from S3 or R2 endpoints
- Network connections to api.telegram.org from non-Telegram-authorized endpoints during web browsing sessions
- HTTP responses with body hashes matching known campaign resource hashes
- Directory structures containing invite.php, meeting.html, update.html, open.php, process.php pattern
- PHP scripts with Telegram Bot API integration and emoji-marked notification messages
False Positive Assessment
Medium — ConnectWise ScreenConnect is legitimate RMM software used by many organizations; detections must distinguish authorized deployments from rogue instances by checking relay hostnames, role parameters, and installation context. Cloud storage services (S3, R2) and Telegram API have many legitimate uses, requiring context-aware alerting.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Review endpoint inventories for unauthorized ConnectWise ScreenConnect installations, particularly clients communicating with instance-*-relay.screenconnect.com relay hostnames or using y=Guest role parameters.
- Consider blocking known phishing domains and payload delivery URLs at your web proxy or DNS filtering layer, including the S3 and Cloudflare R2 endpoints identified in the report.
- If your EDR supports it, consider creating detection rules for msiexec.exe silent installations preceded by hidden PowerShell processes, and for ScreenConnect client processes with Guest role parameters.
- Evaluate whether blocking api.telegram.org network traffic is feasible for endpoints without a legitimate business requirement, as the campaign exfiltrates victim telemetry via Telegram Bot API.
Infrastructure Hardening
- Consider implementing HTTP response body hashing on web proxies or IDS/IPS to detect recurring campaign resources by their known SHA256 hashes.
- Evaluate whether your email filtering can detect and block messages containing links to the identified phishing domains or to Google Meet/Zoom/Teams lookalike pages.
- If applicable, consider implementing DNS sinkholing for the identified phishing domains and correlating reverse DNS namespace smartpocketmoney.com.
- Review whether your organization's cloud storage policies could be abused similarly; monitor for unauthorized S3 buckets or R2 endpoints hosting executable content.
User Protection
- Consider deploying endpoint controls that alert on or block downloads of executable and MSI files originating from web pages preceded by software update or meeting-themed content.
- Evaluate whether your EDR can detect and alert on UAC bypass attempts using the RunAs verb from hidden PowerShell or batch file contexts.
- If supported by your tooling, consider application allowlisting for RMM software to prevent unauthorized ScreenConnect installations from registering with unapproved relay instances.
- Consider monitoring for newly installed services with names matching ScreenConnect Client patterns, especially those installed from temp directories or user Downloads folders.
Security Awareness
- Consider incorporating training on fake software update social engineering into existing awareness programs, emphasizing that legitimate app stores do not present update prompts through web browser modals.
- If applicable, remind users that Google Meet, Zoom, and Microsoft Teams do not require software downloads from third-party websites to join meetings.
- Consider adding guidance for employees to verify unexpected meeting invitations, document signing requests, and electronic card invitations through out-of-band channels before clicking links.
- Where appropriate, educate users that legitimate government agencies such as the SSA do not require software installation to view statements or verify identity.
MITRE ATT&CK Mapping
Resource Development
Initial Access
Stealth
Discovery
Command and Control
Additional IOCs
- Domains:
paperorbit[.]cloud- DocuSign-themed phishing domainpaperwhale[.]cloud- MS Teams Transcript-themed phishing domainseoulapp[.]tech- MS Teams Transcript-themed phishing domainaspenbio[.]top- U.S. Social Security Administration-themed phishing domainecoprune[.]site- Document Review-themed phishing domainbotdip[.]cloud- Document Review-themed phishing domaincloudhudson[.]cloud- Document Review-themed phishing domainjumpingcloud[.]top- Secure Document Portal-themed phishing domainpixelio[.]site- Secure Document Portal-themed phishing domainloanix[.]club- Adobe Acrobat-themed phishing domainurbanio[.]online- Adobe Acrobat-themed phishing domaincryptora[.]pw- Adobe Acrobat / Blue Mountain-themed phishing domainislund[.]site- Adobe Acrobat / Blue Mountain-themed phishing domainjceic[.]top- Adobe Acrobat / Blue Mountain-themed phishing domainsoapano[.]site- Adobe Acrobat / Blue Mountain-themed phishing domaintalent[.]qpon- Adobe Acrobat / Blue Mountain-themed phishing domaintonora[.]cloud- Adobe Acrobat / Blue Mountain-themed phishing domainpaypig[.]online- PUNCHBOWL Electronic Card Invitation-themed phishing domaincloudyspoon[.]store- PUNCHBOWL Electronic Card Invitation-themed phishing domainpaylad[.]online- PUNCHBOWL Electronic Card Invitation-themed phishing domainyellowrabbit[.]site- PUNCHBOWL Electronic Card Invitation-themed phishing domainebrobot[.]cloud- Infrastructure correlated via smartpocketmoney.com reverse DNSbiohera[.]space- Infrastructure correlated via smartpocketmoney.com reverse DNStabearl[.]cloud- Infrastructure correlated via smartpocketmoney.com reverse DNSrenewfog[.]space- Infrastructure correlated via smartpocketmoney.com reverse DNS
- Urls:
hxxps://stcdubai[.]com/googlemeet/- Fake Google Meet phishing page initiating the update social engineering chainhxxps://pub-39190877e0004c3a84a95c22db10d23b[.]r2[.]dev/Secure_Document_Viewer.msi- Cloudflare R2 hosted ScreenConnect MSI disguised as Secure Document Viewerhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/6707110503/20260708_184219_e1bdbdc9.msi- Cloudflare R2 hosted ScreenConnect MSI installerhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/8405320297/20260630_154034_69eb5426.msi- Cloudflare R2 hosted ScreenConnect MSI installerhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/1907797257/20260626_181121_3cf54548.msi- Cloudflare R2 hosted ScreenConnect MSI installerhxxps://pub-b42d42acf73b4e5887636c7e58ea9500[.]r2[.]dev/msi/1907797257/20260621_150522_cb1eadfc.msi- Cloudflare R2 hosted ScreenConnect MSI installerhxxps://kilodz[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://ieabgtsk[.]s3[.]us-east-1[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://btegiacmq[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://bieagtdk[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://baigetrc[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://ea-bnitkmg[.]s3[.]us-east-2[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installerhxxps://prjtmna[.]s3[.]us-east-1[.]amazonaws[.]com/ScreenConnect.ClientSetup.msi- AWS S3 bucket hosting ScreenConnect MSI installer
- File Hashes:
C71DDFA376B2A86BAE93D46D997742502D127979A8774402C936EC6832BB91D0(SHA256) - Hash of QUOTE 36C.bat / Q4 2026 SETTLEMENT.bat batch file415DA0881AE2019A096BBA596C1643FEE0EC44D08682F748F88A39665D99A375(SHA256) - Hash of InviteJuly26.bat / Q12 2026 SETTLEMENT.bat batch file424ebbbec7a6498badfe12e973247252ee4f5f789c3f2007e716ec745a3cc55b(SHA256) - Hash of Q10-2026SETTLEMENT.bat batch file9e6875670e605367ad86dfb62b0a42714129c2e83da49e43674a1beb4ada9867(SHA256) - Hash of InvitedBlue26.bat batch file246ec497890d94776ccf6bfb14bd5a3568cde115b72926527841255fa0a44aa7(SHA256) - Hash of FileDOC0626-14.bat batch file5B6CFF6946771502AAB7F60038FF20B7E45D19EF5C5ED95B4FF0B8193CA4B75A(SHA256) - Hash of 2026Q1SETTLEMENT.bat batch file9cc0dfa491f5eebdca6a351e699886946b0b96fdbcb7d454ea15af2fffdf6b93(SHA256) - HTTP resource hash of static campaign resource reused across ~1.7k phishing frameworksd30d6a29859de6ff8232e346a044322cc53a02bca1d78bdaa8edde74def982db(SHA256) - HTTP resource hash of static campaign resource reused across ~120 phishing frameworks7f8907a05b737e1b4ddedfe870cb99c0352a2cd8373671c26854d9711b88849b(SHA256) - HTTP resource hash of static campaign resource reused across ~70 phishing frameworks
- File Paths:
ScreenConnect.ClientSetup.exe- ConnectWise ScreenConnect client installer delivered by phishing pagesScreenConnect.ClientSetup.msi- ConnectWise ScreenConnect MSI installer variant delivered via S3 and Cloudflare R2INVOICE2515.bat- Batch file payload performing UAC bypass and silent ScreenConnect MSI installationInvitedBlue26.bat- Batch file payload themed as invitation for Blue Mountain eCard lureViewDoc271.bat- Batch file payload themed as document viewer for document review lureInviteJuly26.bat- Batch file payload themed as July invitationFileDOC0626-14.bat- Batch file payload themed as document fileSecure_Document_Viewer.msi- ScreenConnect MSI disguised as secure document viewer on Cloudflare R2SSA_STATEMENT_EN_US.zip- ZIP archive containing ScreenConnect installer disguised as SSA statement on Cloudflare R2Invitation_RSVP.exe- ScreenConnect installer renamed to reinforce invitation-themed social engineering lure
- Command Lines:
- Purpose: Silent MSI installation of ScreenConnect client | Tools:
msiexec.exe| Stage: Execution |msiexec /i <path> /quiet /qn /norestart - Purpose: UAC bypass via RunAs verb to execute batch file with elevated privileges in hidden window | Tools:
powershell.exe,cmd.exe| Stage: Execution - Purpose: Download ScreenConnect MSI from encoded URL after ASCII decoding | Tools:
powershell.exe| Stage: Ingress Tool Transfer
- Purpose: Silent MSI installation of ScreenConnect client | Tools:
- Other:
8918656905:AAHsvi-QVq2HcIx0mcyR62tBzzjNFk-_ags- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 8125456434, header: New Visit, File Download Attempt)8492930076:AAGoNZ9WBED4lDgombN5eldcKfeqsaSdFjM- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 8125456434, header: New Visit, File Download Attempt)8723817827:AAEfo4zFxtKnGMqHTCp5uTRSd4XQZzYkJ_8- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 8125456434, header: New Visit, File Download Attempt)8191938769:AAEphC1pwXopJ4TYpFAg-w0j3CqyWmsmoWs- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 5138732873, header: Private Invite Accessed, payment remittance downloaded)8957453635:AAHM2zNR2lVtbKPUTWOGD120E3e52BXtVKI- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 8656647889, header: Private Invite Accessed, payment remittance downloaded)7756152516:AAHidtLYHu2dT-S8m7g_cxBqah05Ka0hYq8- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 7856937699, header: Private Invite Accessed, payment remittance downloaded)7878021789:AAF-JI1ZXX7PqI3nUctoNNSzgGsrPZAhiAQ- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 6516548207, header: payment remittance downloaded)8958903633:AAFKF1j_leSUZcbHmNUGW-gFAufwxA3vI6M- Telegram Bot API token used for victim telemetry exfiltration (Chat ID: 6615566444, header: Page Visit, Button Clicked — Download Triggered)