CSAFI Remote Access Incident: A Wake-Up Call for Cyber Resilience
Lessons from a Real-World Remote Access Incident Targeting Cyber Resilience Efforts


CSAFI Remote Access Incident: A Wake-Up Call for Cyber Resilience
Author: Deon Engelbrecht - Vice President of Cyber Enablement, CSAFI
Executive Summary
While CSAFI’s focus has been on helping food and beverage organizations become more cyber resilient, we had a real cybersecurity wake-up call of our own.
What first looked like a suspicious download became something more serious: a fake “urgent Microsoft update” message and the repeated installation of a remote-access tool called ScreenConnect, also known as ConnectWise ScreenConnect.
ScreenConnect itself is a legitimate remote support platform. Many IT teams, managed service providers and software vendors use tools like this every day. But that is exactly what makes this type of incident dangerous. Legitimate remote access tools can be abused when installed without consent, hidden behind fake urgency or paired with another mechanism that brings them back after removal. In our case, removing the visible ScreenConnect client was not enough. It came back after reboot.
The real question was not simply: “How do we remove this?”
It was: “What is reinstalling it?”
The answer appeared to be a separate remote-access service running from a JWrapper Remote Access folder under ProgramData. Once that service was stopped, disabled, deleted and the related files were removed, ScreenConnect stayed gone after reboot.
We had anticipated this. As CSAFI’s visibility and mission grew, we knew we would become a target. This awareness mattered. We did not dismiss the warning signs as a software glitch. We disconnected, investigated, traced the persistence mechanism and removed the remote-access chain before it could escalate.
Without this resilience and awareness, it could have ended very differently.
This incident reinforced a central CSAFI message: cyber resilience is not theoretical. It is practiced in moments of uncertainty, when someone sees something unusual, pauses, disconnects, investigates and escalates.
Why This Incident Matters
Remote access tools are essential to modern IT support. They allow internal IT teams, managed service providers, software vendors and equipment partners to troubleshoot systems, maintain endpoints and reduce downtime. But the same capabilities that make these tools useful also make them attractive to attackers.
Remote access software can provide:
- Persistent access
- Screen viewing
- File transfer
- Command execution
- Software installation
- Background connectivity after reboot
When such tools are installed without governance or consent, they can turn an ordinary laptop into a controlled access point.
For food and beverage organizations, the risk is especially serious. Remote access tools can create a bridge between a single compromised endpoint and the broader operational ecosystem: plant operations, supplier communications, quality records, ERP systems, production schedules and vendor support channels.
In an industry where uptime, traceability, food safety, cold-chain integrity and customer trust are mission-critical, unauthorized remote access is not just an IT issue. It can become an operational resilience issue.
A compromised laptop may not directly control production equipment, but it can expose email, credentials, customer data, supplier communications, business documents, ERP access, cloud drives, VPN sessions and planning files.
In a manufacturing environment, endpoint risk can quickly become business risk.
Incident Overview
The incident began with a suspicious executable download. The file was treated as untrusted and was not intentionally executed. Initial precautions were taken, including avoiding execution, checking installed programs, reviewing Windows services, inspecting startup entries and using Windows Security.
Soon after, the laptop began showing a concerning blue-screen-style message claiming that Microsoft was installing an urgent update and warning not to disconnect the PC. This did not behave like a normal Windows update.
Further inspection revealed the installation of: ScreenConnect Client (46dc4704faad25dd)
The client was removed through the Windows Installer uninstall command associated with its product entry. After removal, initial checks showed no visible ScreenConnect application, service, startup entry or scheduled task. However, after reboot, ScreenConnect returned. That changed the nature of the incident. It was no longer just an unwanted program. It was recurring persistence.
The Critical Question: What Was Reinstalling It?
Once ScreenConnect returned after removal, the investigation shifted from removal to persistence.
The system showed a ScreenConnect service running automatically as a Windows service from: C:\Program Files (x86)\ScreenConnect Client (46dc4704faad25dd)\ScreenConnect.ClientService.exe
The service was configured to auto-start and run under the LocalSystem account. That alone was concerning because it meant the tool could return after reboot and operate with elevated privileges.
The more important discovery came from reviewing recent installers, service creation events and file locations. A folder was identified under: C:\ProgramData\JWrapper-Remote Access\ Inside that folder were remote-access-related components including service files, launchers, gateway components and logs. A Windows service named: Remote Access Service was running automatically from: C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\SimpleService.exe
A suspicious temporary MSI file was also found under a Windows Temp folder, with a timestamp closely aligned to a ScreenConnect reinstall event: C:\Windows\Temp\toolbox...\danceya.msi
The likely chain was:
- A remote-access persistence component remained installed.
- It ran as an automatic Windows service.
- It triggered or supported the reinstallation of ScreenConnect.
- ScreenConnect returned after removal.
- Removing ScreenConnect alone did not fix the problem.
- Removing the underlying Remote Access Service broke the loop.
Once the Remote Access Service was stopped, disabled, deleted and its related files removed, ScreenConnect stayed removed after reboot.
Key Indicators Observed
The following indicators were observed during the incident. They are included as examples of what users and IT teams may want to investigate if they see similar behavior.
Suspicious installed application
ScreenConnect Client (46dc4704faad25dd)
ScreenConnect service path
C:\Program Files (x86)\ScreenConnect Client (46dc4704faad25dd)\ScreenConnect.ClientService.exe
Suspicious persistence folder
C:\ProgramData\JWrapper-Remote Access\
Suspicious service
Remote Access Service
Suspicious service executable
C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\SimpleService.exe
Suspicious temporary installer path
C:\Windows\Temp\toolbox...\danceya.msi
Observed behavior
- Fake urgent Microsoft update-style message
- Remote access software installed without informed consent
- ScreenConnect returned after uninstall
- Remote access service ran automatically at startup
- ScreenConnect was installed as an auto-starting LocalSystem service
- Removal of the visible tool alone did not stop reinstallation
Lessons for Business Leaders
1. Remote access governance is no longer optional
Every organization should know which remote support tools are approved, who is allowed to install them, when they may be used and how sessions are authorized. If a remote-access tool appears without approval, treat it as a serious incident.
This is especially important in food and beverage organizations where vendors, OEMs, integrators, software partners and managed service providers may all require occasional support access. That access must be governed, time-bound, approved and visible.
2. Reinstallation is a major red flag
If unwanted software comes back after removal, something else is likely reinstalling it.
That “something else” may be:
- A Windows service
- A scheduled task
- A startup entry
- A hidden installer
- A browser component
- A remote management tool
- A fake updater
- A compromised support agent
- A persistence mechanism under ProgramData, AppData or Temp
Removing the visible application may not remove the threat.
3. Fake urgency is part of the attack
A blue screen or pop-up claiming to be an urgent Microsoft update should never be taken at face value, especially if it appears outside the normal Windows Update process. Urgency is often used to stop people from thinking clearly.
The message may say:
- Do not turn off your PC
- Microsoft is installing an urgent update
- Call support immediately
- Do not disconnect
- Your system is infected
- A technician is required
The right response is to pause, disconnect from the internet and escalate.
4. Endpoint risk is business risk
A compromised laptop can expose:
- Credentials
- Cloud files
- Customer data
- Supplier communications
- Business documents
- Password manager sessions
- ERP or planning access
- VPN access
- Sensitive internal communications
In a manufacturing or food and beverage environment, this can create operational, commercial and reputational exposure. The incident may start on one endpoint, but the consequences can spread across the business.
5. Non-technical users need simple playbooks
Most users are not trained forensic analysts. They do not need to be.
They need simple, memorable steps:
- Disconnect from the internet.
- Do not click anything.
- Do not call any number shown on screen.
- Do not allow a remote session.
- Take a photo of the suspicious screen if possible.
- Contact IT or a trusted security professional.
- Change important passwords from a separate clean device.
- Do not reconnect until the device has been checked.
Cyber resilience improves when people know what to do under pressure.
How to Test a Windows System Using PowerShell
The following PowerShell checks can help identify unauthorized remote access tools, suspicious services and persistence mechanisms. These commands are intended for defensive inspection of your own computer or systems you are authorized to manage. Run PowerShell as Administrator before using these commands.
1. Check for ScreenConnect or ConnectWise installed applications
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*,
HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
Where-Object {
$_.DisplayName -match "ScreenConnect|ConnectWise"
} |
Select-Object DisplayName, Publisher, InstallDate, UninstallString |
Format-List
Good result: no unexpected ScreenConnect or ConnectWise entries.
If an entry appears and the tool is not approved, investigate before reconnecting the device to the network.
2. Check for suspicious remote access services
Get-CimInstance Win32_Service |
Where-Object {
$_.Name -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access" -or
$_.DisplayName -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access" -or
$_.PathName -match "ScreenConnect|JWrapper-Remote Access|SimpleService"
} |
Select-Object Name, DisplayName, State, StartMode, PathName |
Format-List
Good result: no unexpected services related to ScreenConnect, ConnectWise, JWrapper, SimpleHelp, SimpleGateway or Remote Access.
Pay close attention to services running from:
- C:\ProgramData\
- C:\Users\<username>\AppData\
- C:\Windows\Temp\
- C:\Users\<username>\Downloads\
3. Check startup entries
Get-CimInstance Win32_StartupCommand |
Where-Object {
$_.Name -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access" -or
$_.Command -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access"
} |
Select-Object Name, Command, Location, User |
Format-List
Good result: no unexpected remote access tools configured to launch at startup.
4. Check scheduled tasks
Get-ScheduledTask |
Where-Object {
$_.TaskName -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access" -or
$_.TaskPath -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access"
} |
Select-Object TaskName, TaskPath, State
Good result: no unexpected scheduled tasks related to remote access tools.
If unwanted software returns after uninstall, scheduled tasks are one of the first places to check.
5. Search common locations for suspicious remote access files
$paths = @(
"$env:USERPROFILE\Downloads",
"$env:USERPROFILE\Desktop",
"$env:USERPROFILE\AppData\Local\Temp",
"$env:ProgramData",
"C:\Windows\Temp"
)
foreach ($p in $paths) {
if (Test-Path $p) {
Get-ChildItem -Path $p -Recurse -Force -ErrorAction SilentlyContinue |
Where-Object {
$_.LastWriteTime -gt (Get-Date).AddDays(-14) -and
($_.Name -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access|Support|Update|Client|Setup|Install|Remote" -or
$_.Extension -match "\.exe|\.msi|\.ps1|\.bat|\.cmd|\.vbs|\.js")
} |
Select-Object FullName, LastWriteTime, Length
}
}
Good result: no unknown executables, MSI installers or scripts in suspicious locations.
Be especially cautious with files under:
- C:\Windows\Temp\
- C:\ProgramData\
- AppData\Local\Temp
- Downloads
6. Check recent Windows Installer events
Get-WinEvent -FilterHashtable @{
LogName='Application'
ProviderName='MsiInstaller'
StartTime=(Get-Date).AddDays(-7)
} |
Where-Object {
$_.Message -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|Remote Access"
} |
Select-Object TimeCreated, Id, ProviderName, Message |
Format-List
This can show when a tool was installed or removed. Look for repeated installation events after removal.
7. Check service creation events
Get-WinEvent -FilterHashtable @{
LogName='System'
Id=7045
StartTime=(Get-Date).AddDays(-7)
} |
Where-Object {
$_.Message -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access"
} |
Select-Object TimeCreated, Id, Message |
Format-List
Event ID 7045 can show when a new service was installed.
This is especially useful when trying to understand how an unwanted tool became persistent.
8. Check for running remote access processes
Get-CimInstance Win32_Process |
Where-Object {
$_.Name -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote" -or
$_.CommandLine -match "ScreenConnect|ConnectWise|JWrapper|SimpleHelp|SimpleGateway|Remote Access"
} |
Select-Object ProcessId, Name, ExecutablePath, CommandLine |
Format-List
Good result: no unexpected remote access processes.
If a suspicious process is running, disconnect from the internet before taking further action.
9. Confirm Microsoft Defender PUA protection
Potentially unwanted application protection can help block unwanted software, bundlers and suspicious installers.
Set-MpPreference -PUAProtection Enabled
Get-MpPreference | Select-Object PUAProtection
Good result:
PUAProtection
-------------
1
10. Run a full Microsoft Defender scan
Start-MpScan -ScanType FullScan
After the full scan, also run Microsoft Defender Offline from the Windows Security interface:
Windows Security → Virus & threat protection → Scan options → Microsoft Defender Antivirus Offline scan → Scan now
What To Do If You Find Something Suspicious
If PowerShell checks reveal an unauthorized remote access tool:
- Disconnect from the internet immediately.
- Do not interact with any suspicious update screen.
- Do not allow remote access.
- Capture screenshots or photos if possible.
- Record the service name, install path and uninstall string.
- Check whether the tool returns after uninstall.
- If it returns, look for the persistence mechanism.
- Run Defender Offline and a full scan.
- Change important passwords from another clean device.
- Escalate to IT or a trusted cybersecurity professional.
If remote access software repeatedly returns after removal, treat the endpoint as compromised and consider a full Windows reinstall.
Recommendations for Food and Beverage Organizations
CSAFI members and food and beverage companies should treat remote access governance as a core cyber hygiene issue.
Create an approved remote access inventory
Document which remote support tools are authorized. Include tools used by IT, MSPs, OEMs, integrators, automation vendors, SaaS providers and consultants. If a tool is not on the list, it should not be allowed.
Review vendor access
Many food and beverage organizations depend on outside support. Vendor access should be:
- Approved
- Logged
- Time-limited
- Revoked when no longer needed
- Reviewed periodically
- Separated from general user accounts where possible
Monitor for remote access tools
Organizations should monitor for tools such as:
- ScreenConnect / ConnectWise Control
- AnyDesk
- TeamViewer
- SimpleHelp
- LogMeIn
- GoToAssist
- Splashtop
- RustDesk
- Atera
- Syncro
- NinjaOne
- RemotePC
- Zoho Assist
- Other RMM or support agents
The issue is not that these tools are always bad. The issue is whether they are approved, expected and governed.
Watch for services running from unusual locations
Services running from these locations deserve attention:
- C:\ProgramData\
- C:\Users\<user>\AppData\
- C:\Windows\Temp\
- C:\Users\<user>\Downloads\
Legitimate software can run from these folders, but remote-access persistence in these paths should be investigated.
Train users on fake updates
Employees should understand that fake update screens, fake Microsoft warnings and unsolicited support prompts are common social engineering techniques. Legitimate updates should come through approved update channels, not pop-ups, scare screens or remote strangers.
Build a one-page incident playbook
Every organization should have a short response guide that tells users what to do if they see suspicious remote access behavior.
The first instruction should be simple:
Disconnect first. Investigate second.
CSAFI Perspective
This incident reinforces why CSAFI’s work matters.
The food and beverage sector is essential. It depends on trusted operations, trusted suppliers, trusted systems and trusted people. Cybersecurity is not an abstract IT issue. It is part of business continuity, food supply resilience, operational confidence and industry trust. When you begin helping others improve their defenses, you should expect to be tested yourself. Whether this incident was opportunistic or targeted, the lesson is the same: visibility creates responsibility. If CSAFI is helping the industry speak more openly about cyber resilience, then we must also model the behavior we advocate.
That means:
- Taking warning signs seriously
- Responding calmly
- Investigating persistence
- Sharing lessons learned
- Helping others avoid the same mistake
- Turning an incident into awareness
Cybersecurity is not only about advanced tools, acronyms or technical controls. It is about helping people recognize when something feels wrong, giving them permission to stop and building simple response habits before a small endpoint incident becomes a larger business problem.
Remote access is powerful. It needs governance, visibility and trust.
Practical Checklist: What To Do First
If you suspect unauthorized remote access:
- Disconnect from Wi-Fi or unplug Ethernet.
- Do not click the suspicious screen.
- Do not call any number shown.
- Do not grant remote access.
- Take a photo of the screen if possible.
- Check installed apps for unknown remote tools.
- Check services, startup entries and scheduled tasks.
- Look for recently created files in ProgramData, AppData and Windows\Temp.
- Remove the visible remote access client.
- Find what is reinstalling it if it returns.
- Run an offline malware scan.
- Change important passwords from another clean device.
- Escalate if the tool returns after removal.
Warning Signs of Remote Access Abuse
- Fake urgent Microsoft update screen
- Software reinstalling after removal
- Unexpected tools such as ScreenConnect, AnyDesk, TeamViewer or SimpleHelp
- Services running from ProgramData, AppData or Temp
- Unknown MSI installers in C:\Windows\Temp
- Remote access services set to automatic startup
- Unexplained mouse movement, pop-ups or support messages
- Requests to keep the computer connected during a suspicious “repair” or “update”
- A support tool appearing without IT approval
Conclusion
This incident ended well because the warning signs were recognized, the device was disconnected, the visible remote access tool was removed and the persistence mechanism was identified and eliminated.
But the broader lesson is more important: The first removal is not always the real fix.
If remote access software returns after removal, something else is reinstalling it.
For food and beverage organizations, the takeaway is clear. Know which remote access tools are approved. Govern vendor access. Train users to distrust fake urgency. Treat recurring installs as serious. And give non-technical employees a simple playbook they can follow under pressure.
Cyber resilience is not theoretical.
It starts with the next suspicious screen, the next unexpected install and the next person who knows enough to disconnect, pause and escalate.
About the leader

Deon has over 20 years’ experience spanning industrial technology, enterprise software, Manufacturing Execution Systems, Industry 4.0 and cybersecurity, working with food, manufacturing and critical infrastructure organizations across North America, EMEA, APAC and Sub-Saharan Africa. His career bridges IT and OT, with senior leadership roles at Rockwell Automation, Schneider Electric, Invensys (now AVEVA) and Marel. He completed a Master’s-level program in Digital Transformation Leadership at Boston University’s Questrom School of Business, with executive education through MIT Sloan, Harvard Law School, the University of Michigan and The Hong Kong Polytechnic University.