PULSE NAME
Threat Actors abuse signed ConnectWise application as malware builder
WHITE PetrP.73 2025-06-29 Modified: 2025-06-29
74
IOCs
HIGH VOLUME
Since March 2025, there has been a notable rise in malware infections utilizing validly signed ConnectWise software, indicative of bad signing practices exploited by threat actors. This trend is linked to a resurgence of abuse surrounding two vulnerabilities identified in February 2024, specifically CVE-2024-1708 and CVE-2024-1709. The current wave of malicious activities is attributable to a new strain of malware, termed "EvilConwi", which leverages these valid signatures to distribute fraudulent applications. Victims often report infections originating from phishing emails that lead to fake pages masquerading as legitimate applications. For instance, one prevalent scenario involved a user clicking on a OneDrive link that redirected them to a Canva page hiding a malicious ConnectWise installer within a download. Reports indicate that users experience symptoms such as their mouse moving erratically and fake Windows Update prompts during active remote connections, signaling a compromise.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (19 / 74 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 07266cd790cac4be7aa33137980aebe5c7658914 SHA1 of cb8a1a1e90c29461b0503e2c5deac7b673617477128ee3baea4d8134676c8af4 2025-06-29
FileHash-SHA1 119f99426817ac8a2b5f02f70a2a41a979c86dfa SHA1 of d6844a6050d5f6c20a3fe12df28e53a2e46559e6c5017576022372e35ab44ff5 2025-06-29
FileHash-SHA1 174b52d8570e0d4abac30a79939429dd2d004aff SHA1 of 5ccc9ef3e8f7113469f4a46c3aca3939fd53b3561a9fd8ffacd531aa520c5921 2025-06-29
FileHash-SHA1 4607d33ab7bf4d4b9ab936bac6b7cdb80b50e520 SHA1 of 540c9ae519ed2e7738f6d5b88b29fb7a86ebfce67914691ce17be62a9b228e0a 2025-06-29
FileHash-SHA1 4fff34c6ee8a93d474171c8773714cfa6f6c86e8 SHA1 of 573f1eefac3079790a9ab40bdd3530ce34b1d2d1c6fa6703a5a8d81cb190a458 2025-06-29
FileHash-SHA1 5345b8df5c1a5182ff96c14fd1c5f200611fa1cd SHA1 of 98e3f74b733d4d44bec7b1bf29f7b0e83299350143ff1e05f0459571cb49c238 2025-06-29
FileHash-SHA1 54ba33e048eb9560c45d80972509b2645b023114 SHA1 of 6bce39b7d7552dbacbb4bdf06b76b4fed3fbb9fe4042b81be12fbdff92b8d95c 2025-06-29
FileHash-SHA1 5ad3e956f269d1a13b058c8d2c8177eb1afdaff7 SHA1 of 55a228f22f68b8a22967cc5b8b2fcbea66fcaf77bebedfb1f89cd134a0268653 2025-06-29
FileHash-SHA1 665f153955fc662524ba45b76a94bf2bbdc2d125 SHA1 of 1fc7f1ef95f064b6c6f79fd1a3445902b7d592d4ff9989175b7caae66dd4aa50 2025-06-29
FileHash-SHA1 82962d1876b03561895156c22a6e68925e01418d SHA1 of 67b909bbcce486baba59d66e3b4ec4c74dd64782051a41198085a5b3450d00c9 2025-06-29
FileHash-SHA1 876e5a093614b9395d296c8a192479f33e213c0b SHA1 of 7180238578817d3d62fd01fe4e52d532c8b3d2c25509b5d23cdabeb3a37318fc 2025-06-29
FileHash-SHA1 892a4da30edc5143f3e045d55059e747f743149a SHA1 of 6d9442ae6ba5a9f34a47e234b6047f61d8ac129e269199793ebb0bed1ad7e3ba 2025-06-29
FileHash-SHA1 902969fb9f0e363fc36b24190dcbc55054ffacee SHA1 of 41037935246da6f43615d93912bc62811c795ea4082a2bfdbf3eda53a012666e 2025-06-29
FileHash-SHA1 c305f0eca93ffcb0ffecb98f7f1a5451cdf9a0d2 SHA1 of b1c36552556a69ec4264d54be929e458c985b83bbc42fe09714c6dce825ac9a7 2025-06-29
FileHash-SHA1 dced9576d539777a0a0827479e96654c3a86795b SHA1 of 8fc8727b6ddb28f76e46a0113400c541fb15581d2210814018b061bb250cc0e6 2025-06-29
FileHash-SHA1 e0665ff01342ca4ea19361d4386964742d9b47d6 SHA1 of 277ef6c0dcaf0e76291fbde0199dda1ca521c03e77dc56c54f5b9af8508e6029 2025-06-29
FileHash-SHA1 ed02c6f1d5603a4688d74c001155dba38170e20a SHA1 of c0c48de11bc4b70fb546b9a76b6126a355c0a0f4b45ed6b6564d8f3146c9f0af 2025-06-29
FileHash-SHA1 fd4a2707a7bb0ca7eaeae9cd910c93ba7156c3ea SHA1 of 72fe38ad67a26cfd89d1bfc744d33f80277e8eb564b5b92fdac46a9a24d845f3 2025-06-29
FileHash-SHA1 ffa4d46dd37ed2b4b79ac605fe7b7555c74ff479 SHA1 of 28f46446d711208aa7686cdaea60d3a31e2b37b08db7cfb0ce350fcd357a0236 2025-06-29