Product
ScreenConnect
- First Reported
- Sep 22, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- KMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware. KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed
- Depending on the path, attackers either capture credentials and authenticated sessions or deliver files that install tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect. September 2026 Cyber Campaigns Target US and EU With Session Theft, Phishing and Payment Fraud
- One delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
Malware (3)
Threat Actors (5)
MITRE ATT&CK (37)
Vendors (9)
Products (12)
Tools (5)
Industries (8)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.