# Huntress Links ScreenConnect Access to Cyberattacks Against Healthcare Organizations

DevFeed: [Huntress Links ScreenConnect Access to Cyberattacks Against Healthcare Organizations](<https://devfeed.tech/articles/bitter-pill-huntress-54597.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack>)

Author: Team Huntress

Published: 2023-11-09T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Server](<https://devfeed.tech/topics/server.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [indicators-of-compromise](<https://devfeed.tech/tags/indicators-of-compromise.md>), [logs](<https://devfeed.tech/tags/logs.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [windows-server](<https://devfeed.tech/tags/windows-server.md>)

## AI overview

Huntress reports that a threat actor used ScreenConnect and other remote access tools to gain and maintain access to multiple healthcare organizations. The investigation found shared accounts, infrastructure, PowerShell activity, and indicators of compromise across affected endpoints.

## Source excerpt

Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.