Incident Score: Analysis & Impact (CON1778005541)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of ConnectWise's Cyber Attack and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts ConnectWise Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the ConnectWise breach identified under incident ID CON1778005541.
The analysis begins with a detailed overview of ConnectWise's information like the linkedin page: https://www.linkedin.com/company/connectwise, the number of followers: 196320, the industry type: Software Development and the number of employees: 3450 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 707 and after the incident was 688 with a difference of -19 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on ConnectWise and their customers.
A newly reported cybersecurity incident, "Cybercriminals Exploit Microsoft Phone Link to Steal SMS-Based OTPs Without Malware on Mobile Devices", has drawn attention.
A sophisticated cyberattack campaign, active since at least January 2026, has uncovered a novel method to intercept SMS-based one-time passwords (OTPs) by targeting Windows PCs synced with mobile devices without deploying malware on the phones themselves.
The disruption is felt across the environment, affecting Windows PCs synced with mobile devices and Enterprise-managed Windows endpoints, and exposing SMS-based OTPs, credentials, authentication codes.
Formal response steps have not been shared publicly yet.
The case underscores how Ongoing, teams are taking away lessons such as Critical gap in security strategies that prioritize smartphone protection over the desktop environments they sync with. Need for enhanced monitoring of enterprise-managed Windows endpoints, and recommending next steps like Monitor and secure Microsoft Phone Link usage in enterprise environments, Enhance detection of RATs like CloudZ and plugins like Pheno and Implement stricter controls on remote support tools like ScreenConnect.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Supply Chain Compromise: Compromise Software Supply Chain (T1195.002) with high confidence (90%), supported by evidence indicating infection chain begins with a fake ScreenConnect update and User Execution: Malicious File (T1204.002) with moderate to high confidence (80%), supported by evidence indicating malicious update deploys a Rust-compiled loader. Under the Execution tactic, the analysis identified Command and Scripting Interpreter: Windows Command Shell (T1059.003) with moderate to high confidence (70%), supported by evidence indicating cloudZ supports remote command execution and Scheduled Task/Job: Scheduled Task (T1053.005) with high confidence (90%), supported by evidence indicating establish persistence via a scheduled task. Under the Persistence tactic, the analysis identified Scheduled Task/Job: Scheduled Task (T1053.005) with high confidence (90%), supported by evidence indicating establish persistence via a scheduled task. Under the Privilege Escalation tactic, the analysis identified Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002) with moderate confidence (60%), supported by evidence indicating exploits Microsoft Phone Link, a built-in Windows app. Under the Defense Evasion tactic, the analysis identified Obfuscated Files or Information (T1027) with high confidence (90%), supported by evidence indicating obfuscated with ConfuserEx, Process Injection: Dynamic-link Library Injection (T1055.001) with moderate to high confidence (80%), supported by evidence indicating dynamically generates executable functions in memory, Virtualization/Sandbox Evasion: System Checks (T1497.001) with moderate to high confidence (80%), supported by evidence indicating checks for analysis tools like Wireshark, Fiddler, and Sysmon, and Indicator Removal: Timestomp (T1070.006) with moderate confidence (50%), supported by evidence indicating avoids static binary storage on disk. Under the Credential Access tactic, the analysis identified Credentials from Password Stores: Credentials from Web Browsers (T1555.003) with high confidence (90%), supported by evidence indicating supports credential harvesting from browsers, Unsecured Credentials: Credentials In Files (T1552.001) with high confidence (90%), supported by evidence indicating accesses SMS messages and OTPs stored in SQLite database, and Multi-Factor Authentication Interception (T1111) with high confidence (90%), supported by evidence indicating intercept SMS-based OTPs by targeting Windows PCs synced with mobile devices. Under the Discovery tactic, the analysis identified System Information Discovery (T1082) with moderate to high confidence (80%), supported by evidence indicating cloudZ supports host profiling and Process Discovery (T1057) with high confidence (90%), supported by evidence indicating pheno scans for active phone connections by detecting processes like PhoneExperienceHost. Under the Collection tactic, the analysis identified Data from Local System (T1005) with high confidence (90%), supported by evidence indicating accesses the app’s local SQLite database where SMS messages and OTPs are stored and Data from Information Repositories: Confluence (T1213.001) with moderate confidence (50%), supported by evidence indicating harvest credentials and authentication codes. Under the Command and Control tactic, the analysis identified Application Layer Protocol: Web Protocols (T1071.001) with high confidence (90%), supported by evidence indicating establishes an encrypted TCP connection to its C2 server and Data Obfuscation: Protocol Impersonation (T1001.003) with moderate to high confidence (80%), supported by evidence indicating uses rotating user-agent strings to blend with legitimate traffic. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating data exfiltration via encrypted TCP connection to C2 server. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- ConnectWise Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/connectwise/incident/CON1778005541
- ConnectWise CyberSecurity Rating page: https://www.rankiteo.com/company/connectwise
- ConnectWise Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/con1778005541-screenconnect-cyber-attack-january-2026/
- ConnectWise CyberSecurity Score History: https://www.rankiteo.com/company/connectwise/history
- ConnectWise CyberSecurity Incident Source: https://thecyberexpress.com/new-infostealer-pheno-steals-mfa-otps/
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf