ScreenConnect
Exploited or exposed remote-access control planes can become downstream customer ransomware paths.
Research Framing
| Field | Value |
|---|---|
| User Topic | ScreenConnect server exploitation, stolen or forged administrative trust, and malicious ScreenConnect deployment as distinct paths to downstream customer impact. See the ScreenConnect / Storm-1175 / Medusa campaign card. |
| Interpreted Questions | Which ScreenConnect vulnerabilities are confirmed KEVs? Which deployment and version is exposed? Did the attacker exploit the server, steal or forge trust, or install a rogue client? Which technicians, sessions, credentials, customers, backups, and endpoints were reachable? What evidence supports data theft or ransomware impact? |
| Initial Observations | The retained evidence supports three different ScreenConnect risk tracks: the 2024 authentication-bypass/path-traversal chain; the 2025 improper-authentication and vendor security-event/hardening track; and legitimate ScreenConnect clients installed by attackers for persistent access. Those tracks require different version, ownership, evidence, and attribution questions. 1,4,6,15,16,17,18,19 |
| Evidence Boundary | A vulnerable server is not automatically compromised; an installed ScreenConnect client does not prove a ScreenConnect server exploit; and Microsoft’s Storm-1175/Medusa reporting does not attribute every ScreenConnect intrusion to that actor or ransomware family. |
| Source Coverage | 19 retained sources: CISA and NVD records, four ConnectWise vendor records, three Microsoft threat-intelligence reports, three Huntress research records, two secondary reports, and three public-tooling signals. Current through July 18, 2026. |
ScreenConnect Exposure Snapshot
Internet-facing, self-hosted ScreenConnect servers and the administrative trust they hold—not the endpoint agent alone.
CVE-2024-1708, CVE-2024-1709, and CVE-2025-3935 are all in CISA’s KEV catalog; both 2024 flaws have known ransomware use.
One compromised MSP control plane can expose technician sessions, credentials, backups, and multiple managed customers.
11 production checks since July 5; latest 18-Jul-2026 1:00 PM ET returned HTTP 200 with no processing error; next 19-Jul-2026 1:00 PM ET.
1-Topic
This brief examines ScreenConnect as a remote-administration trust path: attackers can exploit an exposed on-premises server, abuse stolen or forged administrative trust, or install their own ScreenConnect client as a legitimate-looking backdoor. These are related ScreenConnect risks, but they are not the same incident mechanism. 4,5,15,16,17,18,19
The ransomware concern is concrete. CISA lists CVE-2024-1708 and CVE-2024-1709 as known exploited with known ransomware campaign use, while Microsoft links exploitation of vulnerable web-facing applications including ScreenConnect to Storm-1175 and Medusa operations. 1,6
For a scoping call, the decisive question is not simply “Do we use ScreenConnect?” It is who operates each server, which build and hosting model it uses, whether the management surface was reachable, what evidence shows unauthorized administration, and which customer systems or data were actually accessible from the compromised trust path.
2-Persona / Audience Lens
| Area | Detail | Action |
|---|---|---|
| MSP leadership | Owns a privileged remote-management platform whose compromise can cross customer boundaries. | Produce a dated server inventory, exposure and patch record, technician/customer reach map, and customer-specific evidence statement. |
| Managed customers | May inherit risk from a provider control plane even when their own endpoint agent is not vulnerable. | Ask which server operated the agent, whether unauthorized sessions reached the environment, and what endpoint evidence was reviewed. |
| SOC / IR / DFIR | Must separate server exploitation, rogue-client installation, valid-account use, and normal technician work. | Preserve IIS, ScreenConnect audit/session/command logs, User.xml, extensions, EDR, identity, backup, and downstream endpoint telemetry. |
| Legal / insurance | Needs evidence-backed decisions across provider contracts, notification, ransomware, privacy, and business interruption. | Separate exposure from compromise and customer reach from confirmed access, collection, exfiltration, or encryption. |
3-BLUF
- The ScreenConnect server is the first scoping priority: the 2024 vulnerabilities affect on-premises server software, not the endpoint agent itself. Cloud-hosted instances were vendor-remediated, while self-hosted operators had to patch and investigate. 4
- Both 2024 flaws are KEVs with known ransomware use: CVE-2024-1709 bypasses authentication; CVE-2024-1708 enables path traversal and can support code execution after administrative access. CISA added them on February 22, 2024 and April 28, 2026, respectively. 1,2,3,4
- The 2025 vulnerability is a separate urgent track: CVE-2025-3935 is also a KEV and affects ScreenConnect 25.2.3 and earlier; ConnectWise directed on-premises partners to fixed 25.2.4 builds and post-patch account, password, MFA, and audit review. 1,14,15
- Patch completion does not prove a clean environment: responders should preserve and review setup requests, User.xml, administrator changes, extensions, queued commands, session connections, source addresses, and endpoint activity before broad cleanup. 4,7,8,15
- MSP compromise can create one-to-many exposure: an attacker controlling the management plane may inherit technician reach into multiple customers, so each customer needs its own access and impact determination.
- The Storm-1175/Medusa chain is high tempo: Microsoft reports credential theft, Veeam password recovery, PsExec movement, NTDS.dit and SAM access, security tampering, Rclone exfiltration, and Medusa deployment through PDQ Deployer or Group Policy. 6
- Data theft and encryption are separate impact questions: Medusa uses double extortion, so restoring systems does not resolve possible stolen-data, notification, contractual, regulatory, or reputational exposure. 6
- ScreenConnect can also be the attacker’s tool rather than the exploited product: 2026 Microsoft campaigns silently installed rogue clients for persistence after phishing, fake software, and DLL sideloading. Do not mislabel those cases as a ScreenConnect server vulnerability. 17,18
- Current hardening goes beyond the 2024 patch: ConnectWise 26.1 strengthens protection and rotation of instance cryptographic material; backups, exported configurations, secrets, extensions, and unusual authentication still require review. 5,16
- What the recent AI Agent runs mean: eleven production checks have completed since July 5. The latest July 18 run detected a published-page state change and completed with HTTP 200 and no processing error; this v2.0 review establishes the stronger evidence baseline for future subscriber deltas.
4-Executive Summary
ScreenConnect is powerful remote-administration infrastructure. When an attacker gains control of an exposed server, steals or forges administrative trust, or installs a rogue client, the same capability used by technicians can provide quiet, legitimate-looking access to managed endpoints. That makes the incident a control-plane and identity problem, not simply a vulnerable software or endpoint-agent problem.4,15,16,17,18
Three KEV records now belong in exposure review. The 2024 authentication bypass and path traversal affected on-premises versions 23.9.7 and earlier; both have known ransomware use. The separate 2025 improper-authentication issue affected 25.2.3 and earlier, and ConnectWise released 25.2.4 plus upgrade and post-patch review guidance. In 2026, ConnectWise further hardened machine-key protection in 26.1 because disclosed cryptographic material could enable forged trusted values, elevated access, and active-session access. 1,4,5,14,15,16
The campaign consequence is not theoretical. Huntress observed ransomware, Cobalt Strike, miners, and additional remote access following 2024 exploitation, while Microsoft’s 2026 Storm-1175 reporting describes a fast path through credential theft, backups, lateral movement, security-control tampering, data exfiltration, and Medusa ransomware. A defensible response therefore preserves evidence first, then contains server and account access, patches and hardens, rotates trust material where warranted, and establishes customer-by-customer reach and impact. 6,19
5-AI Agent Delta Updates
18-Jul-2026 1:00 PM ET — production check completed: the ScreenConnect AI Monitoring Agent recorded a changed page state, returned HTTP 200, and completed without a processing error. This was the eleventh production check since 05-Jul-2026 1:00 PM ET.
Material v2.0 intelligence update: corrected KEV treatment for CVE-2024-1709, added CVE-2025-3935 and current vendor guidance, expanded the Storm-1175/Medusa campaign chain, distinguished rogue-client deployment from server exploitation, upgraded all 32 cards, and linked the related campaign, actor, and KEV records.
Confirmed Page Alerts subscribers receive the changed-card deltas when a material edition is published. Next scheduled production check: 19-Jul-2026 1:00 PM ET.
6-Why It Matters
| Area | Detail | Action |
|---|---|---|
| Control plane | ScreenConnect administrators can open sessions, transfer files, run commands, and reach managed endpoints. | Inventory each server, hosting owner, public exposure, build, administrative identities, and connected customer groups. |
| Inherited trust | An MSP platform can concentrate access across many customers even when no customer endpoint contains the vulnerable server component. | Map which customers, endpoints, credentials, active sessions, and backups were reachable during the suspected window. |
| Attacker tempo | Public exploitation and Microsoft’s ransomware chain show that access can progress rapidly into credential theft, exfiltration, and encryption. | Escalate suspicious administrator or credential-theft activity as active ransomware-prevention work, not a routine vulnerability ticket. |
| Evidence burden | Patching changes the future attack surface but does not answer whether earlier access or persistence occurred. | Preserve server, identity, session, command, extension, endpoint, backup, and network evidence before trust resets and rebuilds. |
7-Timeline
| Date | Event | Why It Matters |
|---|---|---|
| 19-Feb-2024 | ConnectWise released 23.9.8 for CVE-2024-1708 and CVE-2024-1709 affecting on-premises 23.9.7 and earlier. 4 | Original fixed-version baseline. |
| 22-Feb-2024 | CISA added CVE-2024-1709 to KEV with known ransomware campaign use; federal due date February 29. 1 | Confirms the authentication bypass was exploited and ransomware-relevant within days. |
| Feb-Mar 2024 | Huntress observed ransomware, Cobalt Strike, miners, additional RMM, persistence, and other post-exploitation activity. 19 | Shows the access enabled multiple monetization paths, not one actor or payload. |
| 24-Apr-2025 | ConnectWise directed on-premises partners to patched 25.2.4 builds for a separate server-side issue. 15 | Creates a second version and investigation track. |
| 02-Jun-2025 | CISA added CVE-2025-3935 to KEV; federal due date June 23. 1 | Confirms exploitation of the 2025 improper-authentication flaw. |
| 17-Mar-2026 | ConnectWise released 26.1 hardening for instance cryptographic material and session authentication. 5,16 | Extends remediation beyond patching into trust-material protection and rotation. |
| 06-Apr-2026 | Microsoft linked ScreenConnect exploitation within Storm-1175’s high-tempo Medusa operations. 6 | Provides a named, source-bound ransomware campaign chain. |
| 28-Apr-2026 | CISA added CVE-2024-1708 to KEV with known ransomware campaign use; federal due date May 12. 1 | Formally confirms exploitation of the path-traversal flaw. |
8-Incident Response Playbook Ideas
| Area | Detail | Action |
|---|---|---|
| Scope the estate | Find cloud and self-hosted servers, versions, public interfaces, extensions, administrators, and customer groups. | Assign an owner to every instance and document whether the relevant 2024, 2025, and 2026 controls are present. |
| Preserve evidence | Collect IIS/web, ScreenConnect audit/session/command, User.xml, extension, identity, EDR, firewall, proxy, DNS, and backup evidence. | Preserve before patching, deleting users, rotating keys, or rebuilding removes high-value history. |
| Hunt access | Review trailing-slash setup requests, user resets, new admins, unusual extensions, source changes, queued commands, file transfers, and remote sessions. | Separate legitimate technicians from unauthorized actions by time, identity, source, customer, and endpoint. |
| Contain and reset trust | Restrict public management access and disable suspect identities, sessions, extensions, or servers. | Patch to supported current builds; rotate passwords, service secrets, and instance cryptographic material where evidence or vendor guidance warrants. |
| Scope downstream customers | Determine which customer endpoints were reachable and which actually received commands, tools, data access, or ransomware. | Issue customer-specific findings and maintain separate exposure, access, data-theft, and impact statements. |
| Recover and monitor | Rebuild or restore from trusted state, update agents and extensions, validate MFA and logging, and watch for alternate RMM persistence. | Require clean administrative paths and heightened monitoring before normal provider access resumes. |
9-Term Glossary
| Term | Meaning |
|---|---|
| Control plane | The ScreenConnect management surface used to administer sessions, accounts, and remote endpoints. |
| MSP | Managed service provider; a third party that may administer many customer environments. |
| ASP.NET machine key | Server cryptographic material used to sign or protect application values. If disclosed, it may let an attacker forge data the application treats as trusted. |
| Rogue ScreenConnect client | A legitimate ScreenConnect endpoint component installed by an attacker and configured to call the attacker’s server; this does not require exploiting the victim’s ScreenConnect server. |
| Double extortion | Stealing data and threatening publication in addition to encrypting systems. |
| RMM | Remote monitoring and management software. Its legitimate administration capabilities can blend attacker activity into normal IT operations. |
10-TTPs
| TTP | MITRE | Detail |
|---|---|---|
| Exploit public-facing application | T1190 | Exploit exposed ScreenConnect or another vulnerable web application for initial access. 1,6,19 |
| Account manipulation | T1098 | Create or modify ScreenConnect administrator access through setup-flow abuse or post-access administration. |
| Valid accounts | T1078 | Abuse legitimate remote-access, administrator, domain, or backup credentials to blend into normal operations. |
| Credential dumping | T1003 | Recover Veeam passwords and access LSASS, NTDS.dit, or SAM material to expand privilege and reach. 6 |
| Remote services | T1021 | Use ScreenConnect, PsExec, and other administrative paths for downstream access and lateral movement. |
| Impair defenses | T1562.001 | Modify Defender settings and add exclusions before ransomware deployment. 6 |
| Exfiltration over web service | T1567 | Archive files with Bandizip and transfer them with Rclone for double extortion. 6 |
| Data encrypted for impact | T1486 | Deploy Medusa through PDQ Deployer or Group Policy after sufficient privilege is obtained. 6 |
11-Common Questions Q&A
| Question | Answer |
|---|---|
| Is the endpoint agent vulnerable? | The 2024 vulnerabilities were in on-premises server software. Endpoint agents were not directly affected, although a compromised server could use its legitimate reach to control endpoints. |
| Are cloud and on-premises deployments the same? | No. ConnectWise remediated hosted cloud instances, while self-hosted operators had to follow affected-version, upgrade, and investigation guidance. Always establish hosting ownership first. |
| Does vulnerable mean compromised? | No. Exposure creates urgency, and KEV confirms exploitation exists in the wild, but local logs and artifacts must establish whether a particular instance or customer was accessed. |
| Is patching enough? | No. Patching blocks the known flaw going forward; it does not remove unauthorized accounts, extensions, sessions, alternate RMM, stolen credentials, forged trust, or downstream persistence. |
| Does ScreenConnect activity mean Storm-1175 or Medusa? | No. Microsoft supports that attribution for a specific campaign context. Huntress observed multiple actors and payloads, and attackers can also install ScreenConnect as their own tool. |
| When should managed customers be notified? | Use customer-specific evidence: whether the provider control plane could reach the customer, whether unauthorized sessions or commands occurred, and whether data access, exfiltration, or impact is supported. |
12-CVE / Vulnerability References
| CVE | Role | Response |
|---|---|---|
| CVE-2024-1709 1,2,4,7,8 | Authentication bypass that allowed an unauthenticated attacker to reach the setup workflow and establish administrative access on vulnerable on-premises servers. | Verify fixed builds, then review trailing-slash setup requests, User.xml resets, new administrators, commands, sessions, and downstream activity. KEV: known ransomware use. |
| CVE-2024-1708 1,3,4 | Path traversal that could expose files outside intended directories and support code execution after administrative access. | Treat as emergency remediation and retrospective investigation. KEV: known ransomware use. |
| CVE-2025-3935 1,14,15 | Separate improper-authentication vulnerability affecting ScreenConnect 25.2.3 and earlier. | Upgrade through the supported path to fixed 25.2.4 or newer; review users, passwords, MFA, audit logs, sessions, and unsupported Linux/Mac server exposure. KEV: ransomware use unknown. |
| ScreenConnect 26.1 hardening | Protects and allows regeneration of instance cryptographic material used for session authentication; not a substitute for the earlier vulnerability fixes. | Update to 26.1 or later, protect backups/configuration exports, review extensions and secrets, and investigate unusual authentication or administrative actions. 5,16 |
13-IOCs / Observables
| Type | Indicator | Usage |
|---|---|---|
| Web path | /SetupWizard.aspx/ | Hunt IIS and ScreenConnect web logs for the trailing-slash alternate path used in authentication-bypass activity. 7,8 |
| Account artifact | App_Data\User.xml reset or replaced | ConnectWise states a compromised instance may contain a replacement file with only one new user. Preserve the file, timestamps, backups, and related setup requests. 4,16 |
| Administrative behavior | New users, role changes, unusual extensions, queued commands, toolbox items, file transfers, or remote sessions | Export audit and Report Manager data before cleanup and correlate every action to a technician, source, customer, and endpoint. 4,15 |
| Storm-1175 tools | Bandizip, Rclone, PsExec, PDQ Deployer, RunFileCopy.cmd, Defender exclusions | Treat combinations around unexpected privileged activity as escalation pivots for credential theft, exfiltration, and ransomware staging. 6 |
| Credential evidence | Veeam password recovery, LSASS access, NTDS.dit or SAM collection | Prioritize as active ransomware-prevention signals and expand scoping to domain, backup, and connected-system access. 6 |
| Rogue client | Unexpected ScreenConnect.ClientService.exe, client service registry keys, attacker-controlled server parameters, or unsigned/untrusted installers | Distinguish an attacker-installed client from exploitation of the organization’s ScreenConnect server. Validate the server identity, installer provenance, signing state, and connection owner. 17,18 |
| Historical network | 155.133.5[.]14, 155.133.5[.]15, 118.69.65[.]60 | Secondary-source indicators from 2024; investigate if present but do not use as a complete or durable blocklist. 10 |
14-Threat Actor Glossary
| Actor / Cluster | Relationship | Caveat |
|---|---|---|
| ScreenConnect / Storm-1175 / Medusa campaign | Canonical CARDS campaign record connecting the source-backed ScreenConnect access path to Microsoft’s 2026 Storm-1175/Medusa intrusion chain. | Campaign context, not universal attribution. |
| Storm-1175 6 | Microsoft-tracked financially motivated actor exploiting vulnerable web-facing applications and conducting high-tempo Medusa operations. | High confidence for Microsoft-observed activity; do not merge all ScreenConnect exploitation into this cluster. |
| Medusa 6 | Ransomware and double-extortion payload/ecosystem used in the Microsoft-reported Storm-1175 chain. | A Medusa payload does not by itself identify every affiliate or initial-access path. |
| LockBit payload context 19 | Huntress observed a leaked LockBit 3.0 builder-derived encryptor executed through compromised ScreenConnect access. | Payload resemblance is not proof of current LockBit operator control or a single campaign. |
| Other or unattributed operators 17,18,19 | Huntress and Microsoft observed miners, Cobalt Strike, additional RMM, fake-software delivery, and other ScreenConnect abuse. | Retain source-specific mechanics and avoid assigning one actor to all activity. |
15-Talking Points
- ScreenConnect concentrates trust: one compromised management server can provide administrator-like reach into many customer environments.
- There are three ScreenConnect KEVs, not one: the 2024 authentication bypass and path traversal have known ransomware use; the separate 2025 improper-authentication flaw has confirmed exploitation with ransomware use not established.
- The endpoint agent was not the vulnerable component in the 2024 event: scoping begins with the server, hosting model, build, administrators, and session history.
- Rogue ScreenConnect installation is a different path: attackers can deploy the legitimate client as persistence without exploiting the victim’s ScreenConnect server.
- Patch status is one line of evidence: account, session, command, extension, credential, backup, and endpoint review determines whether access became a breach.
- The campaign card is warranted: Microsoft provides a sufficiently specific Storm-1175/Medusa chain to support a source-bound campaign record, while the card explicitly excludes unrelated ScreenConnect abuse.
16-Decision Ready Actions
| Area | Detail | Action |
|---|---|---|
| Executive / MSP leadership | Treat exposed or suspicious ScreenConnect control planes as enterprise and downstream-customer risk. | Require an accountable owner, 24-hour exposure/containment status, and customer-by-customer reach assessment. |
| IT / vulnerability management | Reconcile every deployment against all three KEVs, current supported builds, 26.1 hardening, and extension status. | Patch, restrict management access, document exceptions, and eliminate unsupported server platforms. |
| IR / SOC | Preserve server and downstream telemetry before trust-reset actions. | Hunt unauthorized setup, users, extensions, commands, sessions, file transfer, credentials, alternate RMM, exfiltration, and ransomware staging. |
| Identity / backup / endpoint | Assume privileged remote access may expose domain and backup credentials. | Rotate evidence-supported credentials and secrets, protect backups, enable tamper protection, and contain affected endpoints or administrative paths. |
| Legal / insurance / privacy | Maintain separate findings for vulnerable, exposed, accessed, data-reached, exfiltrated, and encrypted. | Base provider notices, customer communications, coverage, and regulatory decisions on source- and customer-specific evidence. |
17-Exploitable Technology Risks
| Area | Detail | Action |
|---|---|---|
| Internet-facing self-hosted server | Vulnerable, unsupported, or unknown builds expose a privileged administration plane directly to attackers. | Remove unnecessary public access, verify current supported builds, and investigate the pre-patch exposure window. |
| Administrator and service identities | Broad roles, shared credentials, weak MFA, long-lived secrets, and stale users enlarge the blast radius. | Use named least-privilege identities, phishing-resistant MFA where supported, periodic access review, and monitored secret rotation. |
| Machine keys and configuration artifacts | Disclosed cryptographic material, backups, or exported configurations can preserve an authentication-forgery path. | Adopt 26.1 or later hardening, protect archives and secrets, regenerate trust material when evidence or vendor guidance warrants. |
| Extensions and customization | Untrusted, outdated, or unnecessary extensions can expand administrative and configuration exposure. | Inventory, minimize, update, and validate extension provenance and configuration. |
| One-to-many customer reach | A provider control plane can convert one server incident into simultaneous access paths across many customers. | Segment customer groups, restrict technician reach, log every privileged action, and maintain customer-specific response playbooks. |
| Unauthorized ScreenConnect deployment | Attackers can install a legitimate client configured to their own server after phishing or malware delivery. | Allowlist expected instance IDs and servers; alert on new services, installers, callback hosts, and client configuration outside approved inventory. |
19-Tier 0 Through Tier 8 Source Summary
| Tier | Sources | Use |
|---|---|---|
| Tier 0 | CISA KEV and NVD | Controls CVE identity, KEV addition/due dates, and ransomware-use status. |
| Tier 1 | ConnectWise bulletins and advisories | Controls affected/fixed builds, hosting responsibility, upgrade paths, vendor event boundaries, and hardening actions. |
| Tier 1 | Microsoft Threat Intelligence | Controls Storm-1175/Medusa attribution and the distinct 2026 rogue-client campaigns. |
| Tier 2 | Huntress research and incident observations | Controls 2024 exploit mechanics, detection artifacts, and observed multi-actor post-exploitation behavior. |
| Tier 3 | Cybersecurity Dive and The Hacker News | Secondary timeline and historical observable corroboration; never overrides official or primary evidence. |
| Tier 4 | Public exploit repositories | Exploit-availability context only; not attribution, victim proof, or controlling remediation guidance. |
| Tier 5-8 | Unverified social posts, forums, claims, and aggregators | Excluded unless independently validated and materially relevant. |
20-Source Reconciliation
| Claim / Collision | Source-Reconciled Resolution | Operational Use |
|---|---|---|
| CVE-2024-1709 KEV status | CISA added CVE-2024-1709 on February 22, 2024 with known ransomware campaign use. Earlier brief language saying only CVE-2024-1708 was the retained KEV was incorrect and is superseded. 1 | Track and investigate both 2024 flaws, while preserving their distinct roles. |
| 2024 versus 2025 vulnerability | CVE-2025-3935 and the 25.2.4 patch are a separate improper-authentication track, not a continuation of the 2024 setup-flow exploit. 1,14,15 | Use the correct affected/fixed build and evidence window for each incident. |
| 2025 vendor event versus ransomware | ConnectWise tied a small-number cloud-customer event to a sophisticated nation-state actor and explicitly said it was not ransomware and not related to the 2024 vulnerability. 16 | Do not merge that event into Storm-1175/Medusa or the 2024 mass exploitation record. |
| ScreenConnect exploit versus ScreenConnect abuse | Microsoft’s 2026 fake-software campaigns installed a legitimate client as attacker persistence after other delivery methods; the ScreenConnect server was not necessarily exploited. 17,18 | Investigate approved server/instance ownership before assigning root cause. |
| Storm-1175/Medusa attribution | Microsoft supports a named campaign chain; Huntress supports multiple other actors and payloads after 2024 exploitation. 6,19 | Use the campaign card for the Microsoft chain and keep unrelated ScreenConnect activity unattributed unless evidence supports another actor. |
21-About the Contributors
| Contributor | Contribution | Evidence Boundary |
|---|---|---|
| CISA / NVD | KEV status, dates, ransomware-use fields, and canonical CVE records. | KEV proves known exploitation exists; it does not prove a specific organization was compromised. |
| ConnectWise | Affected/fixed builds, cloud/on-prem ownership, upgrade paths, compromise checks, security-event statements, and hardening guidance. | Vendor statements control product scope but do not replace local forensic validation. |
| Microsoft Threat Intelligence | Storm-1175/Medusa campaign mechanics and separate 2026 malicious-delivery campaigns using ScreenConnect clients. | Each report is campaign-specific; do not merge the actor, root cause, or impact across them. |
| Huntress | 2024 exploit reproduction, setup-flow detection, and incident-response observations across multiple post-exploitation paths. | Observed activity is strong practitioner evidence but not a universal actor or victim population. |
| IntelliOS PANDA | Reconciles the source record into 32 decision-oriented cards, CARDS links, Page Alerts, and a monitored version history. | Generated synthesis remains informational and source-bounded; incident conclusions require local evidence and professional judgment. |
22-Real World Examples
| Example | What the Source Supports | Why It Matters |
|---|---|---|
| Storm-1175 / Medusa | Microsoft described vulnerable-web-app access, credential theft, backup-password recovery, lateral movement, security tampering, Rclone exfiltration, and Medusa deployment. 6 | Shows the full pre-encryption chain and supports the campaign card. |
| 2024 SlashAndGrab activity | Huntress observed ransomware, Cobalt Strike, miners, additional remote access, persistence, and varied payload delivery after ScreenConnect exploitation. 19 | Proves the 2024 access path was broadly reusable and not one ransomware-only campaign. |
| 2025 ConnectWise security event | ConnectWise reported a very small number of cloud customers affected by nation-state intelligence collection, patched the service, and explicitly separated the event from ransomware and the 2024 vulnerability. 16 | Demonstrates why source deconfliction is essential even when the same product is involved. |
| 2026 rogue ScreenConnect installations | Microsoft documented signed-malware and fake-software campaigns installing ScreenConnect clients for attacker-controlled persistence. 17,18 | Shows that ScreenConnect can be the post-access tool rather than the exploited product. |
23-Public Victims / Disclosure Matrix
| Publicly Supported Victim Set | Disclosure / Impact | IntelliOS Treatment |
|---|---|---|
| Very small number of unnamed ScreenConnect cloud customers | ConnectWise’s May 2025 advisory says a sophisticated nation-state actor affected a very small number of customers; those customers were contacted. It was not ransomware and not related to the 2024 flaw. 16 | Retain as a separate vendor event; do not identify customers or merge it with the Medusa campaign. |
| Huntress-observed partner/customer environments | Huntress reported more than 1,600 incident reports and multiple post-exploitation behaviors, but the source does not provide a complete named-victim list. 3,19 | Use the scale and behaviors for priority and hunting, not as a named-victim total. |
| Microsoft-observed Storm-1175 targets | Microsoft describes campaign mechanics and impacts without publishing a comprehensive victim roster. 6 | Do not infer any organization was a victim without its own or a primary source’s disclosure. |
24-KEV and CVE Details
| CVE | CISA KEV Status | Decision-Ready Treatment |
|---|---|---|
| CVE-2024-1709 | Added 22-Feb-2024; due 29-Feb-2024; known ransomware campaign use. | Authentication-bypass leg. Verify fixed 23.9.8-or-later lineage and investigate setup/admin artifacts and the entire historical exposure window. 1,2,4 |
| CVE-2024-1708 | Added 28-Apr-2026; due 12-May-2026; known ransomware campaign use. | Path-traversal leg. Patch and retrospectively investigate file access, code execution, persistence, commands, sessions, and downstream reach. 1,3,4 |
| CVE-2025-3935 | Added 02-Jun-2025; due 23-Jun-2025; ransomware campaign use unknown. | Separate improper-authentication issue affecting 25.2.3 and earlier. Follow the 25.2.4-or-later upgrade path and review users, credentials, MFA, logs, and unsupported servers. 1,14,15 |
25-MITRE ATT&CK Lifecycle Mapping
| Phase | Technique | Local Evidence |
|---|---|---|
| Initial Access | T1190 Exploit public-facing application; T1078 Valid accounts | Public exposure, affected build, setup requests, source addresses, successful authentication, and server ownership. |
| Persistence | T1098 Account manipulation; T1219 Remote access software | New or changed admins, User.xml reset, unusual extensions, rogue ScreenConnect clients, alternate RMM, and unexpected services. |
| Execution | T1059 Command and scripting; T1569 Service execution | Queued commands, PowerShell, PsExec, msiexec, file transfers, scripts, PDQ Deployer jobs, and service creation. |
| Credential Access | T1003 OS credential dumping | LSASS, NTDS.dit, SAM, Veeam credential recovery, domain authentication, and newly used privileged accounts. |
| Lateral Movement | T1021 Remote services | Technician/customer sessions, PsExec, domain-controller access, backup-host connections, and cross-customer reach. |
| Defense Evasion | T1562.001 Impair defenses | Defender registry modifications, local exclusions, tamper alerts, security-service changes, and hidden legitimate-tool use. |
| Collection / Exfiltration | T1560 Archive; T1567 Exfiltration over web service | Bandizip archives, Rclone execution/configuration, outbound cloud traffic, staged files, and data-owner scope. |
| Impact | T1486 Data encrypted for impact | Medusa payloads, RunFileCopy.cmd, PDQ or Group Policy deployment, encryption events, ransom notes, and recovery disruption. |
26-Source Weighting / Relevance
| Decision | Controlling Evidence | Do Not Use As a Substitute |
|---|---|---|
| Exploit prioritization | CISA KEV plus NVD CVE identity and vendor affected/fixed versions. | Social urgency, scanner results, or actor claims without version and exposure validation. |
| Patch and hardening | ConnectWise bulletins/advisories for build, hosting, upgrade, trust-material, extension, and account guidance. | Old articles or public exploit repositories as current remediation instructions. |
| Attribution and campaign | Microsoft for Storm-1175/Medusa; Huntress for its observed multi-actor 2024 post-exploitation set. | Payload name, IP overlap, or ScreenConnect presence as standalone attribution. |
| Victim and customer impact | Organization/provider disclosure plus local session, command, identity, endpoint, data, exfiltration, and encryption evidence. | Product exposure, KEV status, or a campaign’s general playbook as proof of specific impact. |
| Detection and hunting | Source-dated primary/practitioner observables combined with environment baselines. | Static historical lists as universal or permanent indicators. |
27-Additional IntelliOS Threat Intel Products on This Topic
| Product | Last Updated | How It Extends This Brief |
|---|---|---|
| ScreenConnect / Storm-1175 / Medusa — Campaign Card | 18-Jul-2026 | Canonical campaign record for the Microsoft-attributed access, credential, lateral-movement, exfiltration, and ransomware chain. |
| Storm-1175 — Threat Actor Card | 02-Feb-2026 | Actor-level context for Microsoft’s financially motivated cluster; keep attribution source-bound. |
| Medusa — Threat Actor Card | 05-Jul-2026 | Ransomware and double-extortion context without assuming every ScreenConnect intrusion uses Medusa. |
| CVE-2024-1708 ScreenConnect Path Traversal — KEV Card | 10-Jul-2026 | Canonical CARDS record for the path-traversal KEV and its remediation context. |
| FortiBleed Fortinet Credential Exposure — Flash Brief | 18-Jul-2026 | Comparator for exposed edge/remote-access trust, credential rotation, and evidence-led scoping. |
28-Notes
| Note | Detail |
|---|---|
| Do not collapse incident states | Vulnerable, internet-exposed, exploitation attempt, administrative access, customer reach, data access, exfiltration, and encryption are different evidence states. |
| Do not collapse root causes | Server exploitation, valid-account abuse, forged machine-key trust, and attacker-installed ScreenConnect clients require separate findings and remediation. |
| Do not over-attribute | Storm-1175/Medusa is a source-backed campaign, but ScreenConnect exploitation and abuse involve multiple operators, tools, and impacts. |
| Daily AI Agent update | The agent has completed 11 production checks since 05-Jul-2026 1:00 PM ET. Latest: 18-Jul-2026 1:00 PM ET, changed status, HTTP 200, no processing error. Next: 19-Jul-2026 1:00 PM ET. |
| Page Alerts | Subscribers can request material-change notifications. Published delta emails identify affected cards and explain what changed and why it matters. |
29-Citations
- [1] CISA. Known Exploited Vulnerabilities Catalog: ScreenConnect entries (Tier 0)Authoritative exploitation and ransomware-use status for CVE-2024-1708, CVE-2024-1709, and CVE-2025-3935.
- [2] NVD. CVE-2024-1709 Detail (Tier 0)Canonical CVE record for ScreenConnect authentication bypass.
- [3] NVD. CVE-2024-1708 Detail (Tier 0)Canonical CVE record for ScreenConnect path traversal.
- [4] ConnectWise. ScreenConnect 23.9.8 Security Bulletin (Tier 1)Vendor remediation baseline for affected ScreenConnect on-prem releases.
- [5] ConnectWise. ScreenConnect 26.1 Security Hardening Bulletin (Tier 1)Vendor hardening guidance, including deployment ownership and machine-key protection.
- [6] Microsoft Threat Intelligence. Storm-1175 Medusa ransomware operations (Tier 1)Primary threat-intelligence source linking ScreenConnect exploitation to Storm-1175 and Medusa ransomware operations.
- [7] Huntress. A Catastrophe for Control: Understanding the ScreenConnect Authentication Bypass (Tier 2)Practitioner analysis of the authentication-bypass chain and hunt mechanics.
- [8] Huntress. Detection Guidance for ConnectWise CWE-288 (Tier 2)Detection guidance for setup-flow abuse and related ScreenConnect artifacts.
- [9] Cybersecurity Dive. CISA adds Microsoft, ConnectWise vulnerabilities to active exploitation catalog (Tier 3)Secondary context around CISA KEV action and operational relevance.
- [10] The Hacker News. Critical Flaws Found in ConnectWise ScreenConnect Software (Tier 3)Secondary corroboration and historical observables.
- [11] GitHub. ScreenConnect AuthBypass RCE repository (Tier 4)Public exploit tooling signal, used only as attacker-enablement context.
- [12] GitHub. ScreenConnect CVE-2024-1709 Exploit repository (Tier 4)Public exploit tooling signal, not attribution.
- [13] GitHub. CVE-2024-1709 Authentication Bypass repository (Tier 4)Public exploit tooling signal that raises exposure-reduction urgency.
- [14] NVD. CVE-2025-3935 Detail (Tier 0)Canonical record for the 2025 ScreenConnect improper-authentication vulnerability.
- [15] ConnectWise. ScreenConnect 25.2.4 Security Patch (Tier 1)Vendor patch, upgrade-path, audit, password-reset, MFA, and unsupported-server guidance for the 2025 issue.
- [16] ConnectWise. ScreenConnect Security Advisories (Tier 1)Primary source for the April/May 2025 security event boundary and March 2026 machine-key hardening guidance.
- [17] Microsoft Threat Intelligence. Signed malware impersonating workplace apps deploys RMM backdoors (Tier 1)Primary 2026 evidence that attackers can install a rogue ScreenConnect client without exploiting a ScreenConnect server.
- [18] Microsoft Threat Intelligence. Poisoned search results to GPU mining: ScreenConnect abuse (Tier 1)Primary 2026 campaign evidence for fake-software delivery, DLL sideloading, silent ScreenConnect installation, persistence, and follow-on access.
- [19] Huntress. SlashAndGrab ScreenConnect post-exploitation in the wild (Tier 2)Incident-response observations of ransomware, a commercial post-exploitation framework, cryptocurrency miners, additional remote access, and other activity.
30-Version Change Log
| Date | Version | Change |
|---|---|---|
| 18-Jul-2026 | v2.0 | Rebuilt all 32 cards to the FortiBleed quality standard; corrected CVE-2024-1709 KEV treatment; added CVE-2025-3935, 2025 vendor-event and patch boundaries, 2026 machine-key hardening, rogue-client campaigns, richer Storm-1175/Medusa tradecraft, CARDS links, victim and source reconciliation, and verified AI Agent production history (11 runs; latest 18-Jul-2026 1:00 PM ET). |
| 23-May-2026 | v1.0 | Initial PANDA generated output retained in the public vault collection. |
| 30-Jun-2026 | v1.1 | Converted to static FortiBleed-style PANDA page with standardized header, card drawer, first-load card defaults, and citation anchors. |
| 04-Jul-2026 | v2.0 | Enabled ScreenConnect AI Monitoring Agent, production Page Alerts subscription support, and card-level delta email support for future published-page changes; no source-backed threat-intelligence content delta added in this pass. |
