AnyDesk Security Breach 2024: What Actually Happened
AnyDesk security breach: source code stolen, certificate compromised, 18,317 credentials on dark web. What IT teams need to know. (CrowdStrike, 2024)
The remote desktop software market is worth $4.49 billion in 2025 and will grow at 12.9% CAGR through 2032 (Future Market Insights, 2025). Yet IT teams are hunting for ConnectWise alternatives at an accelerating pace. The reasons: price hikes of up to 275% on some tiers, a sophisticated 2025 security incident that exploited signed installer infrastructure, and a per-concurrent-session licensing model that frustrates multi-tech teams.
If you're evaluating a ConnectWise ScreenConnect alternative, here's the short version: Splashtop is the strongest direct replacement for MSP remote support, NinjaOne is the best option for teams migrating off the full ConnectWise stack, and Sobrii Remote is the right choice for IT teams managing a known Windows fleet who want remote control built into their asset management platform.
TL;DR: ConnectWise ScreenConnect charges $30/mo (One), $45/mo (Standard), or $55/mo (Premium) per concurrent tech on annual billing. In 2025, attackers discovered they could modify the Authenticode certificate table in signed ScreenConnect installers to redirect connections to attacker-controlled infrastructure while keeping the digital signature valid. ConnectWise patched the issue and rotated certificates. This comparison covers 6 verified ConnectWise alternatives with real pricing as of April 7, 2026.
ConnectWise ScreenConnect has a loyal user base — 4.7/5 on Capterra (1,895 reviews). But 49% of negative reviews on Capterra cite licensing complexity as the primary complaint, and 56% of negative reviews point to recurring stability and compatibility issues.
Three factors are driving migration in 2026.
Prices climbed significantly. According to Splashtop's published analysis, some ConnectWise ScreenConnect tiers saw increases of up to 275%. The per-concurrent-session model ($45/month Standard, annually) hits multi-tech teams hard — every additional parallel session requires an additional license.
The 2025 security controversy damaged trust. In early 2025, researchers identified that ConnectWise ScreenConnect's customized installer architecture stored server configuration data inside the Authenticode certificate table — a field normally reserved for signing metadata. Attackers exploited this by modifying only that table to create malicious installers pointing to attacker-controlled infrastructure, while the original digital signature remained intact. This technique is called "authenticode stuffing." Phishing campaigns distributed files named things like "Request for Proposal.exe" that displayed a fake Windows Update screen while silently establishing connections to attacker servers. G DATA named the malware Win32.Backdoor.EvilConwi. As of May 2025, most major antivirus engines failed to flag these as malicious. ConnectWise responded by revoking the affected certificate, rotating code signing certificates, and changing the installer architecture so configuration is now stored in separate files rather than inside the certificate table. A separate flaw enabling ScreenConnect session hijacking (CVE-2026-3564) was patched in March 2026.
Ecosystem lock-in limits flexibility. ScreenConnect integrates most deeply with ConnectWise Automate (RMM) and ConnectWise Manage (PSA). Teams running a different RMM or PSA don't get those native integrations and pay full price for a tool that sits outside their workflow.
Splashtop is consistently the top recommendation on r/sysadmin and r/msp as a direct ScreenConnect replacement. It was named a G2 Grid Leader in 15 categories in Summer 2025 and reports an NPS of 91–94 — among the highest in the category.
Verified pricing (April 2026):
| Plan | Price | Use case | |------|-------|---------| | SOS (attended support) | $22/user/month (monthly billing available) | Ad-hoc attended remote support | | SOS+10 | ~$26/user/month | + 10 unattended access computers | | SOS Unlimited | $34/user/month | Unlimited unattended access | | MSP License | $259/tech/year | 1 concurrent tech + 10 unattended | | MSP+ License | $399/tech/year | 1 concurrent tech + 300 unattended |
Key advantages: average implementation time of 0.3 months (fastest in category), monthly billing available on SOS plans (unlike ConnectWise ScreenConnect which requires annual commitment on the entry tier), clean interface, solid iOS/Android support.
Watch out for: advanced features like SSO and full audit logging are enterprise-only. The "Business Access" vs "Remote Support" plan distinction confuses new buyers.
G2: 4.8/5 (821 reviews, Summer 2025)
Best for: MSPs and IT technicians who want a direct ConnectWise ScreenConnect replacement for attended and unattended support at a lower price with more billing flexibility.
TeamViewer has the broadest platform support in the market (Windows, macOS, Linux, iOS, Android, Chromebook) and native ITSM integrations with ServiceNow, Salesforce, and Zendesk. It's the reference tool for enterprises that need remote access to truly any device.
Verified pricing (April 2026):
| Plan | Price | Use case | |------|-------|---------| | Remote Access | $24.90/month | 1 user, remote access | | Business | $50.90/month | 1 concurrent session | | Premium | $112.90/month | Up to 15 sessions | | Corporate | $229.90/month | Up to 30 sessions | | Tensor | Custom quote | Enterprise, SSO, DEX, 24/7 support |
Key advantages: AR remote assistance (TeamViewer Assist AR), built-in IoT device management, federated identity (Okta, Azure AD), no dependency on a specific RMM ecosystem.
Watch out for: TeamViewer is frequently cited as the most expensive tool in the category. Its automated commercial-use detection can suspend non-licensed accounts without warning.
G2: 4.5/5 (3,715 reviews)
Best for: Large enterprise IT teams that need maximum cross-platform coverage, ITSM integrations, and no ecosystem lock-in beyond what ConnectWise or NinjaOne offer.
AnyDesk stands out for its DeskRT codec (optimized for low-latency connections on degraded networks) and its on-premises hosting option. For organizations with data sovereignty requirements, it's one of the few alternatives that supports a fully self-hosted deployment.
Verified pricing (April 2026) — in EUR:
| Plan | Price | Scope | |------|-------|-------| | Solo | €23.12/month (annual) | 1 connection, 100 managed devices | | Standard | €39.92/month (annual) | 20 users, 500 devices, session recording | | Advanced | €89.52/month (annual) | 2 connections, 100 users, mass deployment | | Ultimate | Custom quote | 5+ users, 2,000+ devices, SSO, on-prem |
Important: In October 2025, AnyDesk shifted from a per-user billing model to a connection-based model, with price increases of 26–40% depending on the plan. This change significantly impacts MSPs who run many parallel sessions. Verify total cost against your actual session volume before committing.
Key advantages: DeskRT codec (ultra-low latency), lightweight agent (~3MB), on-premises option, custom namespace.
G2: 4.5/5 (1,064 reviews)
Best for: Organizations with on-premises hosting requirements or ultra-low latency needs that are comfortable with the connection-based pricing model.
NinjaOne is not just a remote access tool — it's a complete RMM platform (patch management, monitoring, automation, alerting) where remote support is one integrated component. It's the most relevant option for MSPs migrating off the ConnectWise Automate + ScreenConnect combination who want to consolidate into a single platform.
Pricing (April 2026):
NinjaOne does not publish a fixed pricing grid. Per-device pricing ranges from approximately $1.50 to $3.75/device/month based on volume:
Free implementation and unlimited support are included. No hidden fees.
Key advantages: rated #1 RMM on G2 for 17 consecutive quarters, Windows + third-party patch management rated 9.1/10 on G2, native multi-tenant architecture for MSPs, Splashtop and TeamViewer integrations available as add-ons.
Watch out for: NinjaOne is a full RMM platform — if you only need occasional remote access to a few machines, it's overkill. Remote access in NinjaOne also requires a pre-installed agent; it doesn't support ad-hoc connections to unenrolled machines.
G2: 4.7/5 (1,600+ reviews)
Best for: MSPs managing 50+ endpoints who want to replace the ConnectWise Automate + ScreenConnect stack with a single, fully integrated RMM platform.
Zoho Assist is the most accessible option in this comparison, with a permanent free plan and a $10/user/month entry point. It was recognized as a Gartner Peer Insights Customers' Choice for the 4th consecutive year in 2025 in the Remote Desktop category.
Pricing (April 2026, monthly billing):
| Plan | Price | Scope | |------|-------|-------| | Free | $0 | Limited features | | Remote Support Standard | $10/tech/month | Basic attended access | | Remote Support Pro | $15/tech/month | Session recording | | Remote Support Enterprise | $24/tech/month | 6 concurrent sessions | | Unattended Access Standard | $10/user/month | Unattended access |
Key advantages: permanent free plan, 4th consecutive year Gartner Customers' Choice 2025, native integration with Zoho Desk, CRM, and SalesIQ, lightweight client for end users.
Watch out for: performance lags on low-bandwidth connections, fewer enterprise features than premium tools, session recording storage limited to 5GB ($4/month per additional 5GB).
Gartner Customers' Choice 2025 (4th consecutive year)
Best for: SMBs, teams already in the Zoho ecosystem, and organizations looking for a free entry point before committing to a paid plan.
Sobrii Remote is fundamentally different from every other option in this list. It's not a "send a code to any user's machine" tool like ScreenConnect. It's the remote control module embedded in the Sobrii IT fleet management platform — alongside 12 other modules: asset inventory, security compliance, DEX scoring, Green IT tracking, financial lifecycle management, and more.
This positioning matters. Sobrii Remote is not suitable for ad-hoc support to unenrolled machines. But for an IT team managing a fleet of 200 to 50,000 enrolled Windows devices, it's the only option that delivers remote control alongside hardware data — battery health, CPU performance, storage status, energy consumption, security compliance posture — in a single unified interface.
Pricing (April 2026):
| Plan | Scope | Price | |------|-------|-------| | Starter | 50–200 devices | €20/device/year (min. €2,400/yr) | | Essential | 200–500 devices | €18/device/year (min. €5,400/yr) | | Business | 500–2,000 devices | €15/device/year (min. €9,000/yr) | | Enterprise | 2,000–5,000 devices | €12/device/year (min. €24,000/yr) |
All plans include all 13 modules: WebRTC remote control with 4 privacy levels, inventory, security alerts, energy tracking, financial lifecycle management, and DEX scoring. No per-technician licensing, no add-ons for concurrent sessions.
What makes Sobrii Remote different:
For IT teams and MSPs currently paying separately for a remote access tool, an asset inventory tool, and a monitoring platform, Sobrii consolidates these into a single platform — without adding another tool to the stack.
Compare Sobrii Remote vs ConnectWise ScreenConnectYou're an MSP migrating from ScreenConnect for attended and unattended support and want a direct, cheaper replacement: Splashtop SOS is the safest choice. Monthly billing available, NPS of 91–94, 15 G2 Grid Leader awards in Summer 2025.
You're replacing the full ConnectWise Automate + ScreenConnect stack and want a single consolidated RMM platform: NinjaOne is the benchmark — #1 RMM on G2 for 17 consecutive quarters, with remote support included in the per-device price.
You manage a Windows fleet of 200 to 50,000 enrolled devices and want remote control integrated with your asset management data: Sobrii Remote is the only option combining remote access, hardware inventory, security monitoring, and lifecycle management in one platform — with no per-technician licensing.
You have data sovereignty requirements and need on-premises hosting: AnyDesk Ultimate — verify the new connection-based model matches your session volume before signing.
You're a small team or looking for a free entry point: Zoho Assist — permanent free plan or $10/month paid tier, 4th consecutive year Gartner Customers' Choice 2025.
You need maximum cross-platform coverage and enterprise ITSM integrations (ServiceNow, Salesforce, Zendesk): TeamViewer remains the reference, despite the cost.
Discussing ConnectWise ScreenConnect security in 2026 requires precision. There were multiple distinct incidents.
The authenticode stuffing attack (2025) is the most novel. ConnectWise ScreenConnect's customized installers store their configuration — server address, dialog text, branding — inside the Authenticode certificate table. Attackers found they could modify only that field to redirect connections to attacker-controlled servers while keeping the original digital signature intact. Phishing campaigns used this to deliver fake ScreenConnect installers. G DATA named the resulting malware Win32.Backdoor.EvilConwi. ConnectWise responded by revoking the abused certificate, rotating code signing certificates across ScreenConnect and related products, and changing the installer architecture so configuration data is now stored in separate files outside the certificate table. The 2025.8 security patch addresses this attack vector.
The session hijacking flaw (2026) is a separate issue. In March 2026, ConnectWise patched CVE-2026-3564, a cryptographic signature verification vulnerability that allowed attackers to extract ASP.NET machine keys and perform unauthorized session authentication within ScreenConnect.
CVE-2024-1709 (2024) is a third distinct vulnerability — a critical authentication bypass (CVSS 10.0) patched in February 2024 — unrelated to the 2025 incidents.
If your organization runs ConnectWise ScreenConnect, verify you're on a version released after the 2025.8 security patch and that your customized installers have been regenerated using the new certificate format. Older versions remain exposed.
ConnectWise ScreenConnect's per-concurrent-session model is fundamentally different from the per-technician or per-device models used by competitors. This difference has a direct impact on total cost.
Per concurrent session (ConnectWise ScreenConnect): you pay for each active parallel session. Three technicians working simultaneously require three licenses. A five-person tech team running parallel sessions requires at minimum $225/month (5 × $45 Standard, annual billing).
Per technician (Splashtop, Zoho Assist): you pay per technician regardless of how many sessions they have open simultaneously. More predictable, easier to budget.
Per device (NinjaOne, Sobrii Remote): you pay per managed endpoint regardless of technician count or session volume. Cost scales with fleet size, not with team headcount — typically the most predictable model for growing organizations.
For teams modeling three-year total cost of ownership with growth scenarios, the per-device model is often the most foreseeable.
Migrating a remote access tool is more straightforward than a full RMM migration — but it still requires planning.
Step 1 — Map your actual usage. How many simultaneous sessions at peak load? Is it primarily attended support (technician + end user) or unattended access (servers, maintenance windows)? The answer determines whether you need a concurrent-session or per-technician model.
Step 2 — Evaluate RMM integration. If you run NinjaOne, ConnectWise Automate, or ManageEngine, check native integrations with each alternative. Splashtop integrates natively with NinjaOne. Sobrii Remote integrates with NinjaOne, Intune, SCCM, and ManageEngine.
Step 3 — Run parallel deployments for 30 days. Don't remove ScreenConnect until the alternative is deployed and tested across your full environment, including edge cases (VPN connections, off-domain machines, any macOS endpoints if applicable).
For IT teams managing a Windows fleet and considering tool consolidation, our guide on IT asset inventory best practices covers how to structure a centralized approach before selecting tools.
What is the difference between ConnectWise ScreenConnect, ConnectWise Automate, and ConnectWise RMM? These are three separate products. ConnectWise ScreenConnect is a remote access tool only. ConnectWise Automate is a full RMM platform (monitoring, patching, automation). ConnectWise RMM is a newer cloud-based RMM offering from ConnectWise. They can be used together, but carry separate licenses and costs.
Does the 2025 authenticode stuffing issue affect current versions? No, if you've applied the 2025.8 security patch and regenerated your customized installers. ConnectWise changed the installer architecture so configuration data is no longer stored in the Authenticode certificate table. Verify your instance is fully updated and that your custom installers were recreated after the certificate rotation.
Can Sobrii Remote replace ConnectWise ScreenConnect for ad-hoc support? No — and this distinction matters. Sobrii Remote requires a pre-installed agent on the endpoint. It's the right tool for IT teams managing a fleet of known, enrolled Windows devices. For ad-hoc support to any user (sending a link or code), Splashtop SOS remains the strongest alternative.
Does NinjaOne include remote access in its pricing? Yes — remote support via the NinjaRMM agent is included in the per-device price. NinjaOne also offers Splashtop and TeamViewer integrations as add-ons for additional use cases.
Is AnyDesk cheaper than ConnectWise ScreenConnect? At the Solo annual tier (€23.12/month), AnyDesk is less expensive than ConnectWise Standard ($45/month). But the connection-based model introduced in October 2025 makes the comparison more complex for MSPs running multiple parallel sessions. Compare total cost against your actual session volume.
Is ConnectWise ScreenConnect still safe to use in 2026? Yes, on a fully patched instance (post-2025.8). The authenticode stuffing vulnerability was addressed by ConnectWise. The risk lies in unpatched instances and old customized installers that were distributed before the certificate rotation — those should be replaced immediately.
Is Zoho Assist really free? The Zoho Assist free plan is permanent, with basic features. For professional use with session recording, unattended access, and multiple concurrent sessions, paid plans start at $10/user/month.
ConnectWise ScreenConnect remains a capable tool — particularly for MSPs already invested in the ConnectWise ecosystem. But pricing increases, the per-concurrent-session licensing model, and the 2024–2025 security incidents have pushed many teams to re-evaluate.
For IT teams looking for a ConnectWise alternative in 2026:
For a unified comparison of TeamViewer, AnyDesk, Splashtop, and ScreenConnect alternatives with security certifications and recent CVEs, see our 2026 remote desktop tools comparison.
If you're evaluating Splashtop as the primary alternative, our Splashtop vs TeamViewer comparison covers pricing, security posture, and MSP-specific feature differences in detail.
Ready to find the right ConnectWise alternative for your fleet?
Try Sobrii Remote Explore Sobrii PlatformDiscover how sobrii transforms IT fleet management.
Book a demo