G DATA researchers observe surge in malware infections via Authenticode stuffing originating from ConnectWise clients.

G DATA researchers observe surge in malware infections via Authenticode stuffing originating from ConnectWise clients.

Since March 2025, cybersecurity researchers—most notably from G DATA—have observed a surge in malware infections originating from ConnectWise clients. These infections are linked to a sophisticated technique called Authenticode stuffing, which allows attackers to trojanize legitimate software and deploy malware while bypassing traditional security checks.