IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

ScreenConnect

Exploited or exposed remote-access control planes can become downstream customer ransomware paths.

Remote AccessMSP Trust PathRansomware Exposure
Published
23-May-2026
Brief Version
v2.0
AI Agent Runs
11 production checks
Next AI Monitor
19-Jul-2026 1:00 PM ET
Brief ID
PANDA-FTIB-SCREENCONNECT-2026-001
Template
Flash Threat Brief Template v2.0

Research Framing

ScreenConnect Exposure Snapshot

1-Topic

This brief examines ScreenConnect as a remote-administration trust path: attackers can exploit an exposed on-premises server, abuse stolen or forged administrative trust, or install their own ScreenConnect client as a legitimate-looking backdoor. These are related ScreenConnect risks, but they are not the same incident mechanism. 4,5,15,16,17,18,19

The ransomware concern is concrete. CISA lists CVE-2024-1708 and CVE-2024-1709 as known exploited with known ransomware campaign use, while Microsoft links exploitation of vulnerable web-facing applications including ScreenConnect to Storm-1175 and Medusa operations. 1,6

For a scoping call, the decisive question is not simply “Do we use ScreenConnect?” It is who operates each server, which build and hosting model it uses, whether the management surface was reachable, what evidence shows unauthorized administration, and which customer systems or data were actually accessible from the compromised trust path.

2-Persona / Audience Lens

3-BLUF

  • The ScreenConnect server is the first scoping priority: the 2024 vulnerabilities affect on-premises server software, not the endpoint agent itself. Cloud-hosted instances were vendor-remediated, while self-hosted operators had to patch and investigate. 4
  • Both 2024 flaws are KEVs with known ransomware use: CVE-2024-1709 bypasses authentication; CVE-2024-1708 enables path traversal and can support code execution after administrative access. CISA added them on February 22, 2024 and April 28, 2026, respectively. 1,2,3,4
  • The 2025 vulnerability is a separate urgent track: CVE-2025-3935 is also a KEV and affects ScreenConnect 25.2.3 and earlier; ConnectWise directed on-premises partners to fixed 25.2.4 builds and post-patch account, password, MFA, and audit review. 1,14,15
  • Patch completion does not prove a clean environment: responders should preserve and review setup requests, User.xml, administrator changes, extensions, queued commands, session connections, source addresses, and endpoint activity before broad cleanup. 4,7,8,15
  • MSP compromise can create one-to-many exposure: an attacker controlling the management plane may inherit technician reach into multiple customers, so each customer needs its own access and impact determination.
  • The Storm-1175/Medusa chain is high tempo: Microsoft reports credential theft, Veeam password recovery, PsExec movement, NTDS.dit and SAM access, security tampering, Rclone exfiltration, and Medusa deployment through PDQ Deployer or Group Policy. 6
  • Data theft and encryption are separate impact questions: Medusa uses double extortion, so restoring systems does not resolve possible stolen-data, notification, contractual, regulatory, or reputational exposure. 6
  • ScreenConnect can also be the attacker’s tool rather than the exploited product: 2026 Microsoft campaigns silently installed rogue clients for persistence after phishing, fake software, and DLL sideloading. Do not mislabel those cases as a ScreenConnect server vulnerability. 17,18
  • Current hardening goes beyond the 2024 patch: ConnectWise 26.1 strengthens protection and rotation of instance cryptographic material; backups, exported configurations, secrets, extensions, and unusual authentication still require review. 5,16
  • What the recent AI Agent runs mean: eleven production checks have completed since July 5. The latest July 18 run detected a published-page state change and completed with HTTP 200 and no processing error; this v2.0 review establishes the stronger evidence baseline for future subscriber deltas.

4-Executive Summary

ScreenConnect is powerful remote-administration infrastructure. When an attacker gains control of an exposed server, steals or forges administrative trust, or installs a rogue client, the same capability used by technicians can provide quiet, legitimate-looking access to managed endpoints. That makes the incident a control-plane and identity problem, not simply a vulnerable software or endpoint-agent problem.4,15,16,17,18

Three KEV records now belong in exposure review. The 2024 authentication bypass and path traversal affected on-premises versions 23.9.7 and earlier; both have known ransomware use. The separate 2025 improper-authentication issue affected 25.2.3 and earlier, and ConnectWise released 25.2.4 plus upgrade and post-patch review guidance. In 2026, ConnectWise further hardened machine-key protection in 26.1 because disclosed cryptographic material could enable forged trusted values, elevated access, and active-session access. 1,4,5,14,15,16

The campaign consequence is not theoretical. Huntress observed ransomware, Cobalt Strike, miners, and additional remote access following 2024 exploitation, while Microsoft’s 2026 Storm-1175 reporting describes a fast path through credential theft, backups, lateral movement, security-control tampering, data exfiltration, and Medusa ransomware. A defensible response therefore preserves evidence first, then contains server and account access, patches and hardens, rotates trust material where warranted, and establishes customer-by-customer reach and impact. 6,19

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-Incident Response Playbook Ideas

9-Term Glossary

10-TTPs

11-Common Questions Q&A

12-CVE / Vulnerability References

13-IOCs / Observables

14-Threat Actor Glossary

15-Talking Points

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Tier 0 Through Tier 8 Source Summary

20-Source Reconciliation

21-About the Contributors

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Source Weighting / Relevance

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Citations

30-Version Change Log