← Back to list

Screenconnect super-admin credential harvesting uses evilginx

TL;DR: Aitm phishing using evilginx targets screenconnect super-admins via amazon ses in low-volume campaigns to harvest credentials and…

Yaniv · 2025-08-30 11:00 · 0 claps · 1.4 min read paywalled
#evilginx #screenconnect #phishing #amazon-ses #aitm
Open on Medium ↗
Wiki topics: MKT · Marketing · General 🔒 · Cybersecurity

Screenconnect super-admin credential harvesting uses evilginx

TL;DR: Aitm phishing using evilginx targets screenconnect super-admins via amazon ses in low-volume campaigns to harvest credentials and session tokens, posing an initial-access risk for ransomware.

What’s new / why it matters Sustained low-volume campaigns have been identified that specifically target senior IT personnel with super-admin privileges in ScreenConnect cloud environments. The use of an AITM proxy built on the EvilGinx framework enables adversaries to intercept session cookies and credentials even when some MFA methods are present, increasing the risk of silent account takeover. Delivery via Amazon SES helps the phishing emails appear legitimate and reduces the likelihood of automated blocking based on sending reputation.

Technical breakdown Adversaries craft spear phishing messages aimed at directors, managers, and security staff who hold elevated ScreenConnect permissions. When a target interacts with a malicious link, the AITM proxy mediates the session and captures authentication tokens exchanged between the user and the legitimate service. The campaign’s low-volume distribution model — often under 1,000 emails per run — suggests a deliberate operational security posture to avoid bulk-detection controls.

Detection & mitigation themes Detection should prioritize behavioral telemetry over static indicators. Monitor for anomalous login patterns on privileged accounts, unusual session token reuse, and deviations in browser fingerprinting or IP geography. Enforce strong, phishing-resistant MFA methods where supported, restrict super-admin rights and apply least-privilege controls, and instrument logging around session issuance and token usage. Review email sending patterns from service providers such as Amazon SES and apply rules to flag atypical or newly provisioned sending identities.

Limitations / unknowns The source material focused on tactics and delivery rather than providing specific IoCs, hashes, or domains. Without published indicators, defensive efforts must rely on telemetry, process hardening, and privilege management. Attribution and the full scope of post-compromise activity remain unstated.

TAGS: #EvilGinx #ScreenConnect #Phishing #Amazon_SES #AITM

SOURCE: https://www.mimecast.com/threat-intelligence-hub/screenconnect-super-admin-credential/


메타데이터
post_id
d99ce445b5e9
slug
screenconnect-super-admin-credential-harvesting-uses-evilginx-d99ce445b5e9
url
https://medium.com/@hasamba/screenconnect-super-admin-credential-harvesting-uses-evilginx-d99ce445b5e9
canonical_url
https://medium.com/@hasamba/screenconnect-super-admin-credential-harvesting-uses-evilginx-d99ce445b5e9
author_url
https://medium.com/@hasamba
status
ok
fetched_at
2026-06-14 16:15:44