{"id":11692,"date":"2026-03-25T13:06:53","date_gmt":"2026-03-25T13:06:53","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11692"},"modified":"2026-03-25T13:06:54","modified_gmt":"2026-03-25T13:06:54","slug":"connectunwise-how-threat-actors-abuse-connectwise-installer-as-builder-for-signed-malware","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/connectunwise-how-threat-actors-abuse-connectwise-installer-as-builder-for-signed-malware\/","title":{"rendered":"ConnectUnwise: How Threat Actors Abuse ConnectWise installer as Builder for Signed Malware"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">ConnectUnwise: How Threat Actors Abuse ConnectWise installer as Builder for Signed Malware<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In March 2025, we noticed and started tracking an unusually high number of ConnectWise-based malware. ConnectWise is a remote desktop application usually used by tech support to provide remote assistance. This new malware campaign weaponized trust in an unexpected way: by delivering validly signed ConnectWise ScreenConnect installers repurposed as remote access malware. These binaries were distributed via phishing emails, cloud platforms or AI related websites. These samples managed to pass traditional AV detection signature checks and appear benign \u2013 all while handing attackers control of the victim\u2019s desktop without visible warnings such as tray icons or prompts or with fake Windows update messages and application icons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A technique known as Authenticode stuffing made this campaign possible. Custom configuration data of ConnectWise such as command-and-control server addresses, user messages, background images or UI suppression flags are embedded into the installer\u2019s certificate table \u2013 a section not covered by Authenticode\u2019s hashing. This allows threat actors to build their own remote access malware while retaining ConnectWise\u2019s valid authenticode signature.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our analysis compared different variations of ConnectWise samples which revealed that only differences between the binaries were found within the certificate data. Using tools such as PortexAnalyzer and Authenticode Lint, we extracted this data, reverse engineered its structure and wrote a config extractor. To detect abused ConnectWise installers, we created YARA rules which search for suspicious configurations strings (such as those controlling UI elements).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the Certificate Authority has revoked the abused certificate as of June 2025, numerous variations of the malware remain in circulation using similar techniques. In line with this, we\u2019ll be presenting how we have managed to detect this unusual form of malware with the hopes of shifting the balance of power between cyber threats and defense.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Lance-Jansen-Caoile-Go.png\" alt=\"\" class=\"wp-image-11693\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Lance-Jansen-Caoile-Go.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Lance-Jansen-Caoile-Go-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Lance-Jansen-Caoile-Go-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Lance-Jansen-Caoile-Go-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong>Lance Jansen Caoile Go &#8211; GData AV Lab Inc<\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lance Go is a cybersecurity professional with 3 years of experience in the field. He mainly focuses on malware research and is always on the lookout for new and interesting threats.&nbsp; Throughout his career, he has sought out opportunities to learn from more experienced professionals to continuously refine and improve his own workflow. He is currently pursuing a Master\u2019s Degree in Computer Science at the University of the Philippines Diliman, where his thesis focuses on image-based malware analysis. Outside of academics and work, Lance enjoys a variety of hobbies including freediving, flying drones, playing badminton, and building automations. His friendly and inquisitive nature allows him to meet people from diverse backgrounds and learn skills across a wide range of fields.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Karsten-Hahn.png\" alt=\"\" class=\"wp-image-11694\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Karsten-Hahn.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Karsten-Hahn-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Karsten-Hahn-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Karsten-Hahn-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong><strong>Karsten Hahn &#8211;<\/strong> <strong>GData Cyberdefense AG<\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Karsten Hahn has a Master&#8217;s Degree in Computer Science from HTWK Leipzig. His master thesis about static Portable Executable analysis won the FBTI Award in 2015, which is doted at 1000 Euro. Since 2015 he works for GDATA CyberDefense AG. At the time he started as Malware Analyst, moved to a Lead Engineer position in 2022, where he was responsible for protection engineering of GDATA&#8217;s new MEDR product. He became Principal Malware Researcher in 2024 and is now responsible for threat research, blog article writing and internal trainings.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back ConnectUnwise: How Threat Actors Abuse ConnectWise installer as Builder for Signed Malware In March 2025, we noticed and started tracking an unusually high number of ConnectWise-based malware. ConnectWise is a remote desktop application usually used by tech support to provide remote assistance. This new malware campaign weaponized trust in an<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/connectunwise-how-threat-actors-abuse-connectwise-installer-as-builder-for-signed-malware\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11692","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11692"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11692\/revisions"}],"predecessor-version":[{"id":11695,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11692\/revisions\/11695"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}