ConnectWise

MITRE ATT&CK: S0591 View on attack.mitre.org

Aliases: ScreenConnect, ConnectWise

First seen
2016-01-01 00:00:00
Malware type
rat
Operating systems
windows
Related IoCs
1251 (1125 malicious)
Last IoC activity
2026-09-02 04:04:06
Profile updated
2026-07-07 12:52:16

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

ConnectWise is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and GOLD SOUTHFIELD to connect to and conduct lateral movement in target environments.

Recent IoC activity

1,127 malicious indicators in Maltiverse are attributed to ConnectWise (S0591). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname cloudsynn.com 2026-09-02 1
file sample f11d8914cde3d49c842b735ba6220553d8eb1ee1a3efeeb9e13bd5e43518cbd5.bin 2026-09-02 3
file sample cb04a8a6904ecf3b5bcd60b712451277aa11567a177764495ed822e68b021e7d 2026-09-02 2
file sample Login.Gov-client.ClientSetup.msi 2026-09-02 3
file sample ScreenConnect.ClientSetup.msi 2026-09-02 3
file sample 5700715b1f7cc10e3a6ec3836d88067637a7055f36260d1e1c91d4db65eb4dbd 2026-09-02 2
file sample ScreenConnect.ClientSetup.exe 2026-09-01 2
file sample ScreenConnect.ClientSetup.exe 2026-09-01 4
file sample support.client.exe 2026-09-01 2
file sample ScreenConnect.ClientSetup.exe 2026-09-01 3
file sample ScreenConnect.ClientSetup.exe 2026-09-01 3
file sample support.client.exe 2026-09-01 2
file sample 2026-09-01_c367f434aa20c7309783ad1853f7260d_amadey_elex_glassworm_hellokitty_... 2026-09-01 3
file sample 9f14cbbbcc39cd0cfe493a06c4420a63.exe 2026-09-01 2
file sample support.client.exe 2026-09-01 2
file sample ScreenConnect.ClientSetup.exe 2026-09-01 2
file sample support.client.exe 2026-09-01 4
file sample file 2026-08-31 1
file sample ScreenConnect.ClientSetup.exe 2026-08-31 3
file sample support.client.exe 2026-08-30 4

Detection coverage

  • 10 YARA rules
  • 189 Sigma rules

Malware & tools used

  • Video Capture (attack-pattern)
  • PowerShell (attack-pattern)
  • Screen Capture (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_INDICATOR_RMM_Connectwise_Screenconnect_CERT (yara-rule)
  • SIGNATURE_BASE_Connectwise_Screenconnect_Authentication_Bypass_Feb_2024_Exploitation_IIS_Logs (yara-rule)
  • SIGNATURE_BASE_SUSP_Screenconnect_User_Poc_Com_Unused_Feb24 (yara-rule)
  • SIGNATURE_BASE_SUSP_Screenconnect_User_Poc_Com_Used_Feb24 (yara-rule)
  • SIGNATURE_BASE_SUSP_Screenconnect_Exploitation_Artefacts_Feb24 (yara-rule)
  • SIGNATURE_BASE_SUSP_MAL_Signingcert_Feb24_1 (yara-rule)
  • SIGNATURE_BASE_MAL_CS_Loader_Feb24_1 (yara-rule)
  • SIGNATURE_BASE_MAL_RANSOM_Lockbit_Indicators_Feb24 (yara-rule)
  • SIGNATURE_BASE_MAL_MSI_Mpyutils_Feb24_1 (yara-rule)
  • SIGNATURE_BASE_MAL_Beacon_Unknown_Feb24_1 (yara-rule)

Reports & references

  • Trend Micro — Earth Vetala Muddywater Continues To Target Organizations In T (report)
  • anomali.com — Probable Iranian Cyber Actors Static Kitten Conducting Cyberespionage Campaign Targeting Uae And Kuwait Government Agencies (report)
  • MITRE ATT&CK — S0591 (report)

External references