DEV Community

Mark0
Mark0

Posted on

2026-09-14: Backdoor using ScreenConnect from malicious emailt

This report details a phishing campaign observed on September 14, 2026, which leveraged emails impersonating the Social Security Administration (SSA). The attack chain begins with a malicious email containing a shortened link that redirects victims to a sophisticated landing page designed to mimic an official SSA statement download portal.

Once on the fraudulent site, victims are prompted to download a customized ScreenConnect client installer. This executable acts as a backdoor, establishing encrypted communication with remote relay servers on port 443. The use of legitimate remote desktop software allows attackers to bypass traditional security controls and maintain persistent access to the compromised environment.


Read Full Article

Top comments (0)