Are Recent Wacatac Alerts for ScreenConnect Client a False Positive?

0
3
Asked By MellowCedar47 On

Has anyone else seen Microsoft Defender detect ScreenConnect.ClientService.exe as Wacatac within the past day? Our managed detection and response provider believes the file is malicious, while ConnectWise support says the alert is a false positive. The Defender timeline looks more consistent with a false detection, but I'd like to compare experiences and understand whether this is related to a recent client update or a genuine compromise.

4 Answers

Answered By QuietLantern22 On

We see this occasionally across a large fleet, usually during client updates—only one or two systems in a release cycle. If the software is approved and centrally managed, the detection is more likely a false positive, but confirm that the client version is current and obtained from the official source.

Answered By NorthwindMica6 On

Treat it seriously because remote-access tools are frequently abused. A legitimate installation can still be compromised or replaced. Check whether the device is registered to the expected tenant, review recent logins and account activity, and investigate any unexpected installers, persistence, or outbound connections.

Answered By CopperGlade31 On

There have also been phishing campaigns distributing ScreenConnect installers through compromised business accounts. If the file came from an email, an unapproved download, or a user with administrator rights, assume possible compromise until the machine and access logs are reviewed. Defender deleting the file does not by itself prove the alert was harmless.

Answered By PixelHarbor8 On

Several people are seeing these alerts after ScreenConnect client upgrades. Wacatac and Vigorf detections have appeared intermittently on otherwise normal installations, so this may be a Defender machine-learning false positive. Still verify the file’s signature, hash, installation source, and process activity before dismissing it.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.