You’d think that after a major takedown by the UK’s National Crime Agency (NCA), the FBI, and Europol, the infamous LockBit ransomware gang would be out of action. But no – just days after authorities shut down their website, LockBit ransomware is still being deployed. And this time, it’s coming through security flaws in a popular remote access tool.
If you use ConnectWise ScreenConnect, a tool often used by IT technicians for remote access and support, you need to pay attention. Cybersecurity experts have discovered that hackers are actively exploiting two serious vulnerabilities, using them to spread LockBit ransomware.
Let’s break down what’s happening and what you need to do to stay protected.
What’s Going On?
Cybersecurity researchers from Huntress and Sophos have found that cybercriminals are using two security flaws in ConnectWise ScreenConnect to launch ransomware attacks.
What is ScreenConnect? It’s a remote access tool used by IT technicians to fix computers and servers remotely. Because it gives full system access, it’s a prime target for hackers.
How are hackers using it? Attackers are taking advantage of two critical vulnerabilities to install and run LockBit ransomware, encrypting victims’ data and demanding a ransom.
Why is this dangerous? If your business or IT team relies on ScreenConnect and it’s not patched, hackers could seize control of your system, lock your files, and demand payment to unlock them.
What Should You Do Now?
ConnectWise has issued an urgent security alert urging IT administrators and businesses to patch these vulnerabilities immediately. If you use ScreenConnect, here’s what you need to do right now:
- Update ScreenConnect ASAP – Check for the latest security patches and install them immediately. Leaving the software unpatched is an open door for hackers.
- Check for Suspicious Activity – If your system has been acting strangely or you’ve noticed unexpected logins, investigate immediately. LockBit infections can spread quickly.
- Enable Multi-Factor Authentication (MFA) – Adding an extra layer of security can prevent unauthorised access, even if a hacker gets hold of your password.
- Restrict Remote Access – If possible, limit who can access ScreenConnect remotely and only allow trusted IP addresses.
- Back Up Your Data – Make regular, secure backups so that if ransomware strikes, you can restore your files without paying a ransom.
- Be Extra Cautious with Emails and Links – Many ransomware attacks start with phishing emails. Make sure your team knows not to click on suspicious links or download unexpected attachments.
Why Does This Matter?
LockBit is one of the most dangerous ransomware groups in the world. Even though law enforcement managed to take down their website, the group is still active and spreading attacks.
If you or your IT team use ConnectWise ScreenConnect, failing to patch these vulnerabilities could leave you open to a serious cyberattack. The last thing you want is to wake up to find your files encrypted, your business locked out of its systems, and a ransom note demanding payment.
Final Thoughts: Act Fast to Stay Safe
This is a critical security threat, and if you use ConnectWise ScreenConnect, you need to patch your system immediately. Cybercriminals move fast, and unpatched software is an easy target for attacks.
If you’re an IT admin – update your software, check for unauthorised access, and tighten security settings.
If you’re a business owner – make sure your IT team is aware of this issue and has patched the system.
If you’re an employee – be extra cautious with links, emails, and any unusual system behaviour.
LockBit might have been weakened, but it’s not gone. Stay alert, stay updated, and keep your systems secure.
Have you been affected by a ransomware attack before? Let us know your thoughts – sharing helps others stay safe!