ConnectWise
ConnectWise (ATT&CK S0591) is described in the provided content as a remote access tool that adversaries can abuse on compromised hosts. Reported capabilities include executing PowerShell commands on target machines, taking screenshots, and recording video on remote hosts. The content also notes that ConnectWise is a legitimate, signed remote access tool whose binaries and network communications can blend into normal administrative traffic, making detection difficult, particularly where IT teams also use the software legitimately. It is explicitly associated with the ATT&CK techniques Command and Scripting Interpreter: PowerShell, Screen Capture, and Video Capture. The content further states that GOLD SOUTHFIELD has used ConnectWise to obtain screen captures from victim machines. No specific infection vector or concrete IOC values are provided in the source material.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Execution
2 techniques
Execution
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
2 techniques
Stealth
Discovery
1 technique
Discovery
Lateral Movement
1 technique
Lateral Movement
Collection
2 techniques
Collection
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
Command and Control
3 techniques
Command and Control
MITRE ATT&CK Mapping ... Command and Control Proxy: Multi-hop Proxy T1090.003 ConnectWise cloud relays proxy through OVH backend servers
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote access tool increasingly abused by attackers as a stealthy method for remote access and persistence, blending in with normal IT operations and evading detection.
The content lists ConnectWise as software associated with PowerShell execution, screen capture, and video capture capabilities.
Remote administration software that can execute PowerShell commands on target machines.
Remote administration tool that can record video on remote hosts.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.