App Review Comodo Internet Security vs targeted ransomware attack.

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
me
Another example of using RemoteAdmin against home users (the audience most likely to own a high-performance discrete GPU):

"The operator runs a coordinated SEO poisoning operation that simultaneously masquerades as a broad portfolio of trusted utility brands, where each one serves the same downstream payload chain.
The campaign abuses multiple trusted brands, including: CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. The selection of these brands is deliberate. Each application is favored by PC enthusiasts and hardware-focused users, precisely the audience most likely to own a high-performance discrete GPU, the hardware that makes GPU cryptocurrency mining economically viable.
"

1785356205713.png


In this example, CIS can be compromised, and RemoteAdmin tool is installed. Then a connection to C2 server is established to download/execute the EXE malware (SimpleRunPE.exe = PE loader). The hash of this EXE loader is unknown (so far) to Comodo Valkyrie, so the file is Unrecognized to CIS and contained. As in the previous example, the attack can be mitigated by CIS before the final payload is executed.
 
Even more dangerous attack via the RemoteAdmin tool was reported here:

"During retrospective threat hunting, the Huntress Tactical Response team recently uncovered a large-scale malvertising campaign that has been active since at least January 2026, targeting U.S.-based individuals searching for tax-related documents. The lures are specifically U.S. tax forms (W-2, W-9), and the fake landing pages reference IRS compliance, casting a wide net across employees, freelancers, contractors, and small businesses during filing season. The campaign abuses Google Ads to serve rogue ScreenConnect (ConnectWise Control) installers, ultimately delivering a BYOVD EDR killer that drops a kernel driver to blind security tools before further compromise. Across our customer base, we reported over 60 instances of rogue ScreenConnect sessions tied to this campaign being used as the initial access vector.

The attack chain is layered: dual commercial cloaking services filter out researchers and scanners, trial ScreenConnect instances provide hands-on-keyboard access, a multi-stage crypter evades AV with a 2GB memory allocation trick, and the final payload abuses a previously undocumented Huawei audio driver to terminate Defender, Kaspersky, and SentinelOne processes from kernel mode.
"

In this dangerous & massive attack, after installing the RemoteAdmin tool, a multi-stage crypter (EXE file) was downloaded and executed to finally kill AV/EDR solutions by applying the BYOVD EDR killer.
In the case of CIS, the system could be compromised by the RemoteAdmin tool, but the multi-stage crypter is unknown (so far) in the Comodo Valkyrie Sandbox, so the malware would be auto-contained.
 
In the case of CIS, the system could be compromised by the RemoteAdmin tool, but the multi-stage crypter is unknown (so far) in the Comodo Valkyrie Sandbox, so the malware would be auto-contained.
Some informative really articles here. I'll have to set aside time to read them but sounds like even though bypassed by the remote admin, I'm reading your comments that in all these cases, at the end of it, Comodo sandboxes and contains the unknown payloads. (y)
 
Some informative really articles here. I'll have to set aside time to read them but sounds like even though bypassed by the remote admin, I'm reading your comments that in all these cases, at the end of it, Comodo sandboxes and contains the unknown payloads. (y)

Yes.(y)
So far, I have not found an example of a non-targeted attack in the wild that could fully infect CIS users (CIS Proactive Security configuration).
The only cons are possible system compromise (as with WiseConnect) and malware leftovers.
In the @Shadowra test, you can see some installed malware (not only related to WiseConnect). This can happen because some of the MSI installations simply extract files, copy them to "C:\Program Files" or user AppData folders, and add some registry keys without any reaction from CIS. However, in the end, the installed malware is contained during execution. CIS is not perfect, but secure at home so far. It must be supported by a good malware cleaner to remove leftovers.
 
Last edited:
I compared the results of the CIS test with an older test for Xcitium conducted by @Shadowra three years ago:


There was an interesting difference when managing MSI installations. Xcitium rated msiexec.exe (which hosts opening MSI files) as Unknown and fully contained the installation. In the CIS case, msiexec.exe has been rated as Trusted (not contained).
I wonder if this difference is related to different hardening settings for msiexec.exe in Script Analysis.:unsure:
 
Just want to correct a few things from the above discussions:
1). regarding ScreenConnect, although having a valid signature in order for this malicious form to work (potentially steal) it MUST be able to connect out. I finally found a sample that was able to be installed (leaving the Kaspersky residue seen in the recent video), but when Outbound Connectivity is checked from within Comodo it can be seen that connections were blocked.

2). CF does indeed contain msiexec.
MSI contained.png


Screen Connect.png
 
  • Like
Reactions: Shadowra
Just want to correct a few things from the above discussions:
1). regarding ScreenConnect, although having a valid signature in order for this malicious form to work (potentially steal) it MUST be able to connect out. I finally found a sample that was able to be installed (leaving the Kaspersky residue seen in the recent video), but when Outbound Connectivity is checked from within Comodo it can be seen that connections were blocked.

2). CF does indeed contain msiexec. View attachment 299142

In the test, msiexec.exe is always rated as Trusted for all MSI samples (not only ScreenConnect), so it is not contained.
 
Last edited: