Phishing now arrives from DocuSign, QuickBooks and Dropbox themselves - and passes SPF, DKIM and DMARC. https://intel.threadlinqs.com/threat/TL-2026-3167 #ThreatIntel #Smash #AnyDesk #ScreenConnect

Phishing now arrives from DocuSign, QuickBooks and Dropbox themselves - and passes SPF, DKIM and DMARC. https://intel.threadlinqs.com/threat/TL-2026-3167 #ThreatIntel #Smash #AnyDesk #ScreenConnect
A Power BI phishing campaign uses Microsoft's real domain to install rogue ScreenConnect clients. Learn how it works and how to block it.
#PowerBI #Phishing #ScreenConnect #RMM #RemoteAccess #EmailSecurity #Huntress #CyberSecurity
📢 Campagne de phishing abuse Microsoft Power BI pour déployer des RMM ScreenConnect malveillants
Cet article publié le 7 octobre 2026 par Huntress (blog.huntress.com) documente une campagne de phishing observée à partir du 10…
🟢 vérification factuelle haute
#PowerBI #ScreenConnect #Cyberveille
A legit Power BI page is the lure - then two rogue ScreenConnect clients quietly take over. https://intel.threadlinqs.com/threat/TL-2026-2998 #ThreatIntel #ConnectWise #HideUL #ScreenConnect
Signed ScreenConnect used in phishing ploy: PDF promise hides remote access installer. #Security #CyberAttack #Phishing #ScreenConnect #RemoteAccess #ThreatIntel https://thedailytechfeed.com/phishing-attack-leverages-valid-screenconnect-client-to-enable-remote-takeover/
A validly signed ScreenConnect installer, posing as a PDF, hands attackers remote access. No malware needed. https://intel.threadlinqs.com/threat/TL-2026-2931 #ThreatIntel #ConnectWise #ScreenConnect #WireTransferPhish
A fake payment email linked to genuine ScreenConnect software, configured to connect to an account controlled by the senders.
The software was real; th…
A fake $5,745.65 payment email promised a PDF but downloaded ConnectWise ScreenConnect instead.
If inst…
A new campaign shows how phishing abuses RMM tools for access. See how phishing abuses RMM tools like MSP360 to install ScreenConnect clients.
📢 CVE-2026-84869 : vulnérabilité critique dans ScreenConnect exploitée activement
Cet article analyse la vulnérabilité CVE-2026-84869 affectant ConnectWise ScreenConnect, un outil de gestion à distance largement utilisé…
🟡 vérification factuelle moyenne
#ScreenConnect #ConnectWise #Cyberveille
A validly signed ScreenConnect installer is the payload - no malware needed, just a rigged config. https://intel.threadlinqs.com/threat/TL-2026-2826 #ThreatIntel #ScreenConnect #ConnectWise #Mejuri
Microsoft warns of phishing campaigns abusing a signed MSP360 installer disguised as invites, PDFs, and update prompts. After install, attackers deploy ScreenConnect for persistent remote access and credential theft. #MSP360 #ScreenConnect #RMM
Phishing crews are abusing MSP360 to install ScreenConnect and get hidden remote access. #Security #RMM #Phishing #MSP360 #ScreenConnect #CyberThreats #RemoteAccess #DualRMM https://thedailytechfeed.com/phishing-gang-misuses-msp360-to-install-screenconnect-behind-the-scenes/
Remote tools like MSP360 and ScreenConnect are now used in phishing disguises—Zoom or PDF installs mask full control of PCs. #RemoteAccess #Cybersecurity #MSP360 #ScreenConnect #Phishing https://thedailytechfeed.com/hackers-masquerade-remote-access-tools-as-zoom-pdf-to-hijack-pcs/
CSuite phishing steals M365 tokens via device-code flow, then plants ScreenConnect RMM for hands-on access. https://intel.threadlinqs.com/threat/TL-2026-2802 #ThreatIntel #ScreenConnect #Action1 #Atera
Signed RMM tools as malware: phishing installs MSP360, then silently adds ScreenConnect. https://intel.threadlinqs.com/threat/TL-2026-2788 #ThreatIntel #MSP360 #ConnectWise #ScreenConnect
正規ツールの悪用 #ScreenConnect
■通信先
hxxp[:]//52.197.194[.]156:8040/Bin/ScreenConnect.ClientSetup.msi
■C2
52.197.194[.]156:8041
■ダウンロード
20260928PFD.iso -> g2m.dll, 202609PDF.exe
www.virustotal.com/gui/file/149...
tria.ge/260929-kvltx...
app.any.run/tasks/516a40...
正規ツールの悪用 #ScreenConnect
20260929PDF.iso -> g2m.dll, 202609PDF.exe
www.virustotal.com/gui/file/8a8...
tria.ge/260929-kmvf4...
app.any.run/tasks/4b1d77...
One phishing kit reads your OS then picks: RMM malware, iCloud phish, or a live MFA-stealing bot. https://intel.threadlinqs.com/threat/TL-2026-2704 #ThreatIntel #ScreenConnect #smokeiT_bot #dswagofficebot
Fake desktop app pages for US payroll and HR platforms lured users into installing ScreenConnect, giving attackers hidden remote access and a path to divert paychecks. #PayrollFraud #ScreenConnect #US