Skip to content

Campaign record

ScreenConnect via a fake SSA site

Spoofed US Social Security Administration site delivering ScreenConnect

Status as last assessed
Active
First seen
2025-06-02
Last seen
2025-06-02
Indicators
1
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Government agency impersonation
  • ScreenConnect
  • Open redirector on a legitimate site
  • Phishing email

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

A run observed in June 2025 posed as the United States Social Security Administration to plant ScreenConnect, a commercial remote support product, on the reader's machine. Mail came from a real Brazilian domain that had been broken into, and the footer carried genuine links to the agency's social accounts; the body claimed something was wrong with the recipient's benefits statement. Its button pointed at a Google advertising redirect rather than the destination, so hovering over the link — the habit awareness training teaches — showed nothing useful. Following it produced access-ssa-gov[.]es, a look-alike registered under Spain's country domain, which copied the agency's front page behind a blur. A counterfeit verification pop-up then walked the reader through steps ending in a PowerShell script that fetched and started the remote access tool, handing the operator the device.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
1 of 1
Checks recorded
2
Checks since publication
2
Never checked
0

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology.

Current recorded state

  • 1 Unregistered

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).

Indicators

1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenStateReport an error
domain, shown defanged for safety: access-ssa-gov dot esdomainLure pageAttacker-controlled2025-06-022025-06-02Unregistered2026-08-22Report an error in domain record a1716128-a3c8-473e-a459-cd25577615d4

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “ScreenConnect via a fake SSA site”, campaign ID 64b61ec1, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/64b61ec1/ssa-clickfix-screenconnect

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.