Malware & Threats

Hackers Abuse ConnectWise to Hide Malware

G Data has observed a surge in malware infections originating from ConnectWise applications with modified certificate tables.

G Data has observed a surge in malware infections originating from ConnectWise applications with modified certificate tables.

Threat actors are increasingly tampering with legitimate ConnectWise remote access applications to hide malicious code and compromise systems, G Data warns.

Investigating numerous reports of malware infections originating from ConnectWise clients, G Data discovered the use of Authenticode stuffing to trojanize legitimate software and deploy malware while bypassing security checks.

Authenticode code signing is a technique that allows developers to verify file integrity, but ConnectWise’s use of a workaround to avoid re-signing the software when creating personalized installers opens the door to abuse.

Specifically, the workaround relies on storing configuration data in the certificate table, and attackers use the same method to hide malicious code in the table.

Called Authenticode stuffing, this technique has been abused as part of a campaign tracked as EvilConwi to deliver malware using modified ConnectWise clients that would pass integrity and authenticity checks.

Because the malicious configurations and payloads are stuffed in the configuration table, Windows does not verify their hashes, and the modified installers do not break the valid digital signature.

Advertisement. Scroll to continue reading.

Since March 2025, G Data has observed a surge in ConnectWise abuse for malware deployments and its analysis of a modified app iteration revealed that hackers used Authenticode stuffing not only to hide their malicious code, but to completely hide the installation of a ConnectWise client on the system.

The modified software masquerades as an AI-to-image converter and disables various visual indicators that would alert the user that ConnectWise has been installed.

It also fakes a Windows update, displaying an image of an update screen, instructs the user to keep the system online, and shows various deceptive messages and windows titles, likely to hide that threat actors are connected to the infected system.

“Although Authenticode stuffing is common practice, ConnectWise’s decision to influence critical behavior and its user interface with unauthenticated attributes is clearly dangerous. It entices threat actors to build their own remote access malware with custom icons, background images and text, that is signed by a trusted company,” G Data notes.

The security firm notified ConnectWise of the observed attacks on June 12 and noticed that the company revoked the signature of the observed samples on June 17. SecurityWeek emailed ConnectWise for a statement on the attacks and will update this article if the company responds.

Related: ConnectWise Discloses Suspected State-Sponsored Hack

Related: ConnectWise Confirms ScreenConnect Flaw Under Active Exploitation

Related: ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

Related: SimpleHelp Vulnerability Exploited Against Utility Billing Software Users

Related Content

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Malware & Threats

CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.

Malware & Threats

The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.

Cybercrime

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.

ICS/OT

A PowerShell script included in patch files appears to be triggering false positives by multiple security engines.

Identity & Access

As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations.

Artificial Intelligence

Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version