# ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: SANS Internet Storm Center
- Category: Cyber
- Original publication time: 2026-10-01T05:32:13Z
- First observed by NexusTechWire: 2026-10-01T18:42:00Z
- Original source: https://isc.sans.edu/diary/rss/33388
- NexusTechWire record: https://nexustechwire.com/news/news-5af31d29d4e782516f81

## The brief

SANS handler Xavier Mertens examined an invoice-themed phishing email that linked to a legitimate ScreenConnect installer configured for an attacker-controlled test account. His analysis found a valid ConnectWise signature and no tampering with the signed executable. The case shows how criminals can misuse ordinary remote-access software without developing a new malware program.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T19:16:00Z. Not independent reporting.

Read the full original: [SANS Internet Storm Center](https://isc.sans.edu/diary/rss/33388)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
