Full Report
ConnectWise is warning customers that it is rotating the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise RMM executables over security concerns. [...]
Analysis Summary
# Incident Report: ConnectWise Code Signing Certificate Rotation
## Executive Summary
ConnectWise initiated a proactive rotation of its code signing certificates due to unconfirmed security concerns, potentially linked to observed threat activity. Threat actors were recently observed using phishing campaigns to distribute pre-configured ConnectWise remote access clients disguised as legitimate documents, relying on the existing valid signatures for trust. While ConnectWise did not explicitly confirm the link, this action suggests an effort to mitigate risks associated with compromised or potentially risky signing keys.
## Incident Details
- Discovery Date: N/A (Proactive action taken by ConnectWise, based on warning/threat intelligence in April)
- Incident Date: Rotation began progressively (Affected users advised to ensure updates before June 13)
- Affected Organization: ConnectWise
- Sector: Software/Remote Management and Monitoring (RMM)
- Geography: Not specified (Global impact due to software distribution)
## Timeline of Events
### Initial Access
- Date/Time: Prior to April/Ongoing reports
- Vector: Phishing campaigns targeting end-users.
- Details: Threat actors created phishing sites distributing malicious ConnectWise commercial remote access client applications disguised as Social Security statements to lure victims.
### Lateral Movement
- N/A (The article focuses on the compromise of the signing mechanism/trust, not specific lateral movement within a customer network.)
### Data Exfiltration/Impact
- N/A (No confirmed data exfiltration related to the certificate rotation itself is mentioned, though malware deployment via clients would imply compromise.)
### Detection & Response
- Date/Time: Sophos researcher Andrew Brandt warned about the phishing campaign in April.
- Response actions taken: ConnectWise began progressively rotating its code signing certificates (for Automate, ScreenConnect, and RMM cloud-hosted versions) and mandated that users update agents by a specific date (June 13) to receive new certificates.
## Attack Methodology
- Initial Access: Social Engineering/Phishing convincing users to download and run a disguised ConnectWise client installer.
- Persistence: N/A (The attack vector relied on successfully tricking users into executing the remote access client).
- Privilege Escalation: N/A (Not detailed, but execution of the client itself would gain initial access).
- Defense Evasion: Digital signing of the malicious client application, lending credibility to the executable.
- Credential Access: Not detailed.
- Discovery: Not detailed.
- Lateral Movement: Not detailed.
- Collection: Not detailed.
- Exfiltration: Not detailed.
- Impact: Compromise of systems via the execution of pre-configured, signed remote access clients.
## Impact Assessment
- Financial: Not specified.
- Data Breach: Not specified, but implied risk exists for users who installed the malicious client.
- Operational: Potential service interruption if users failed to update agents before the June 13 deadline.
- Reputational: ConnectWise proactively addressing potential certificate trust issues.
## Indicators of Compromise
- Network indicators: N/A (No specific malicious C2 domains/IPs provided, though attackers used pre-configured servers).
- File indicators: Malicious ConnectWise commercial remote access client applications disguised as Social Security statements.
- Behavioral indicators: Users running downloaded ConnectWise clients from unsolicited sources (phishing hooks).
## Response Actions
- Containment measures: Rotating code signing certificates to invalidate any potentially compromised or suspicious keys.
- Eradication steps: Requiring users to update their agents to receive software signed with new certificates.
- Recovery actions: Ensuring uninterrupted service for cloud-hosted clients post-rotation.
## Lessons Learned
- The digital signature on remote access tools adds a high degree of implicit trust, which can be heavily abused in supply chain/client distribution attacks.
- Continuous monitoring of how threat actors are utilizing seemingly legitimate vendor tools (like pre-configured RMM clients) is crucial for vendor security posture.
## Recommendations
- Organizations deploying vendor RMM/remote tools should verify the source and integrity of all downloaded executables, regardless of digital signature validity, especially if obtained through unsolicited communications.
- ConnectWise should enhance controls around its code signing processes and potentially investigate how threat actors were able to distribute pre-configured, signed clients via phishing hooks.