Phishing emails carrying fake PDF invoices are installing Action1's remote-management agent, SANS ISC handler Xavier Mertens reported. It follows a ScreenConnect campaign he documented a few days earlier that used the same fake-invoice lure.
Publishers:isc.sans.edu
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence72
Huntress tied one rogue ScreenConnect configuration from a Power BI phishing campaign to 22 more endpoints across separate incidents. For defenders, the thing to hunt is a ScreenConnect client their own IT never deployed.
Reality
- Evidence62
- Adoption12
- Hype gap0
- Incentives
- Insufficient
- Confidence60
Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Pluto Security says the SleepyDuck operator re-listed fake Solidity extensions on Open VSX within hours of a takedown, in a stage it calls EtherDuck. Each wave stayed up about 19 hours, long enough for a single install to leave persistent access that the takedown did not remove.
Publishers:pluto.security
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence45
Any.Run's researchers found a phishing kit running in 46 countries whose final payload is a signed copy of ScreenConnect or GoTo Resolve, which moves the defensive question from malware signatures to which remote-access tools may execute at all.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
ConnectWise's September 3 advisory promises a CVE and a fix within the week, so until one lands the only control is a per-role permission change. Huntress says the spread is already worm-like across newly connected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 57%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence64
A single operator is distributing fake "desktop apps" for three US payroll platforms that have no desktop product. Each installer silently sets up ScreenConnect for unattended control of the payroll operator's machine, Allure Security found.
Reality
- Evidence60
- Adoption10
- Hype gap+20
- Incentives40
- Confidence55
Microsoft says affiliate Storm-2570 has run the same remote access and exfiltration tools whether it deploys Qilin, DragonForce, Anubis or BERT ransomware. Detections built on those tools can catch the operator before any payload runs.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence55
Huntress says three of its SOC investigations began with document lures and ended with victims installing rogue ITarian and ScreenConnect clients, and its responders now find RMM abuse in almost 40% of the incidents they work.
Reality
- Evidence45
- Adoption50
- Hype gap+20
- Incentives78
- Confidence48
CVE-2026-84869 affects ScreenConnect clients before 26.6.5. ConnectWise rates it Priority 1 High and tells on-premise partners to treat the update as an emergency change, then reinstall host clients and access agents.
Publishers:connectwise.com
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−12
- Incentives62
- Confidence58
The bug lets files be pushed and executed through a remote session the host already approved, and CISA says attackers are doing it now. It is ScreenConnect's fourth entry on the KEV catalog since 2024.
Reality
- Evidence62
- Adoption42
- Hype gap+18
- Incentives68
- Confidence58
ConnectWise's stopgap is to switch off file transfers in ScreenConnect, and with CISA's exploited-flaw listing now carrying a three-day federal deadline, more than 1,000 exposed servers still run the unpatched build.
Reality
- Evidence62
- Adoption70
- Hype gap+12
- Incentives45
- Confidence60
ConnectWise fixed CVE-2026-84869 in ScreenConnect 26.6.5 after Huntress traced a modified client dropping four VBScript files onto machines it held active sessions with. CISA gave federal agencies three days.
Reality
- Evidence64
- Adoption58
- Hype gap+12
- Incentives55
- Confidence62
buildOne report1 publisher A guidance post on dev.to argues you cannot catch remote support abuse by identifying the binary. The eight signals it recommends instead all lean on baselines most teams have never written down, and that is where the cost sits.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+28
- Incentives78
- Confidence58
ConnectWise says the fix arrives later this week. Until it does, the only step it offers is a hand-edited per-role permission change that turns off file transfer inside support sessions, on cloud and on-premises alike.
Reality
- Evidence42
- Adoption34
- Hype gap+12
- Incentives66
- Confidence52
The joint advisory says the actors never installed the clients. Portable copies ran in the user's context, pointed at attacker-run RMM servers, and installation controls never saw them.
Reality
- Evidence74
- Adoption63
- Hype gap−8
- Incentives32
- Confidence70