Executive Summary
In September 2025, cybersecurity researchers identified a sophisticated attack leveraging the ConnectWise ScreenConnect remote monitoring tool to deliver AsyncRAT, a potent remote access trojan. Threat actors exploited legitimate RMM infrastructure to establish unauthorized access, bypass defenses, and deploy a VBScript-based loader on victim systems. Once installed, AsyncRAT facilitated unauthorized credential harvesting and cryptocurrency theft from compromised hosts, exposing sensitive business and personal data. The campaign’s use of trusted IT management software as an initial entry vector complicated detection and posed significant risks to organizations relying on remote administration tools.
This incident underscores an increasing security challenge: the abuse of legitimate remote management solutions by attackers to evade detection and propagate malware. As identity-driven and tool-based attacks surge, businesses must re-examine their controls, segmentation, and monitoring to counter exploitation of sanctioned IT utilities.
Why This Matters Now
The prevalence of threat actors hijacking legitimate remote software amplifies urgency for organizations to scrutinize RMM tool deployments and enforce zero trust principles. This incident shows that attackers are innovating to leverage trusted apps as covert attack channels, making fast detection and granular access controls more critical than ever.
Attack Path Analysis
The attacker initially compromised systems by exploiting the ConnectWise ScreenConnect remote access service, using it to deploy a custom loader and AsyncRAT malware. After establishing this foothold, they escalated privileges via remote script execution, gaining broader system and user access. Using this access, the attacker may have performed lateral movement across internal hosts, leveraging living-off-the-land techniques. The AsyncRAT established command and control through encrypted outbound channels to its operators. Sensitive data and credentials were exfiltrated using these remote connections, and the ultimate impact involved data theft and risk to cryptocurrency wallets, implicating business and personal asset loss.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited legitimate remote access via ConnectWise ScreenConnect to gain initial foothold, leveraging RMM misuse as the primary entry point.
Related CVEs
CVE-2025-3935
CVSS 7.2An improper authentication vulnerability in ConnectWise ScreenConnect allows for ViewState code injection attacks, potentially leading to remote code execution if machine keys are compromised.
Affected Products:
ConnectWise ScreenConnect – <= 25.2.3
Exploit Status:
exploited in the wildCVE-2024-1709
CVSS 10An authentication bypass vulnerability in ConnectWise ScreenConnect allows attackers to circumvent security controls, potentially leading to remote code execution.
Affected Products:
ConnectWise ScreenConnect – <= 23.9.7
Exploit Status:
exploited in the wildCVE-2024-1708
CVSS 8.4A path traversal vulnerability in ConnectWise ScreenConnect allows attackers to access restricted directories, potentially leading to remote code execution.
Affected Products:
ConnectWise ScreenConnect – <= 23.9.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Remote Access Software
Command and Scripting Interpreter: Visual Basic
Ingress Tool Transfer
Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder
Obfuscated Files or Information
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Unique Identification and Authentication
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA ZTMM 2.0 – Continuous Identity, Credential, and Access Management
Control ID: ZT-IA-02
NIS2 Directive – Access Control Policies
Control ID: Art. 21(2)(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AsyncRAT exploiting ConnectWise ScreenConnect creates severe risks for software companies using RMM tools, enabling credential theft and lateral movement through development environments.
Information Technology/IT
IT service providers face critical exposure as AsyncRAT leverages legitimate ScreenConnect access to deploy remote trojans, compromising client networks and sensitive data.
Financial Services
Remote access trojan threats targeting RMM infrastructure pose significant risks to financial institutions' encrypted traffic, requiring enhanced east-west traffic monitoring and segmentation.
Health Care / Life Sciences
Healthcare organizations using ScreenConnect face HIPAA compliance violations from AsyncRAT credential theft, necessitating stronger egress security and anomaly detection capabilities.
Sources
- AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Cryptohttps://thehackernews.com/2025/09/asyncrat-exploits-connectwise.htmlVerified
- ConnectWise ScreenConnect Vulnerability Exploited: CISAhttps://www.crn.com/news/security/2025/connectwise-screenconnect-vulnerability-exploited-cisaVerified
- AsyncRAT deployed via ConnectWise ScreenConnect exploitationhttps://www.scworld.com/brief/asyncrat-deployed-via-connectwise-screenconnect-exploitationVerified
- ConnectWise ScreenConnect 23.8 Security Fixhttps://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fixVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust networking, segmentation, internal traffic controls, and robust egress policy enforcement would have contained attacker movements, blocked unauthorized remote access, and disrupted command-and-control and data exfiltration at multiple points in the kill chain.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized external access and remote desktop protocol exposure.
Control: Zero Trust Segmentation
Mitigation: Restricts host-to-host communication and limits blast radius of privilege escalation attempts.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized movement across internal workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks suspicious outbound C2 channels.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks signature-based data exfiltration over known malicious channels.
Enables rapid detection and intervention in anomalous or destructive activity.
Impact at a Glance
Affected Business Functions
- IT Support
- Remote Management
- Data Security
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive client data, including credentials and financial information, due to unauthorized remote access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation policies to isolate RMM access and critical workloads.
- • Enforce strict egress filtering and FQDN controls to block unauthorized outbound RAT and C2 traffic.
- • Deploy east-west traffic monitoring and microsegmentation to prevent lateral movement post-compromise.
- • Integrate inline IPS and anomaly detection for early identification of malicious access and exfiltration attempts.
- • Continuously audit RMM tools and restrict their exposure with granular, identity-based firewall controls.



