EvilConwi

First seen
2023-06-15 00:00:00
Malware type
rat, trojan
Last IoC activity
2026-07-21 20:30:11
Profile updated
2026-07-07 15:00:29

Targeted industries: technology-and-telecommunications professional-services retail-and-hospitality

Context

EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise. This software is a remote access software. Threat actors modify the configuration extensively so that any signs of an active remote connection are removed. EvilConwi often pretends to perform a Windows update by using fake Windows update images embedded in the config. The purpose is to keep the system running while the threat actor connect remotely. Other EvilConwi signs are fake application icons. E.g., it may pretend to be an installer for Zoom and use its icons and application titles in the ConnectWise config.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Evilconwi_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Evilconwi (report)
  • gdatasoftware.com — 38218 Connectwise Abuse Malware (report)

External references