Malware & Threats

Modified ScreenConnect Clients Used in Worm-Like Campaign

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.

Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns.

The worm-like attacks began in late August and start with the rogue clients being deployed on victims’ machines via social engineering.

Following the installation, the malicious ScreenConnect instances have been observed spawning repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files.

Huntress noticed the same attack pattern across different organizations: the rogue ScreenConnect clients were used to propagate their payload to other connected instances, and the attackers created a User Run Key pointing to another VBScript file, for persistence.

In an August 20 attack, a threat actor posing as tech support instructed the victim to execute the Windows’s built-in remote support tool Quick Assist, thus gaining control over the victim’s machine. The hacker then executed the five VBScript files on the system before the attack was blocked.

On the same day, Huntress observed the same VBScript files being deployed in another environment, likely as part of another phishing attack.

Advertisement. Scroll to continue reading.

“The rogue ScreenConnect client almost immediately launched the four VBScript files from the ScreenConnect temporary directory. During the course of the investigation, network telemetry also identified active connections from ScreenConnect to multiple remote IP addresses,” Huntress notes.

The attacker was also seen establishing persistence through the User Run Key, and installing the UltraViewer remote desktop software.

Huntress observed the same files and operations being executed in an August 24 attack that also started with social engineering.

The four scripts deployed by the rogue ScreenConnect clients were designed for perform system reconnaissance, stage payloads, and execute a PowerShell script.

This code executes a second PowerShell script that erases staging evidence, attempts UAC bypass, and installs and conceals a ScreenConnect client that continuously checks for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.

“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress notes.

On Thursday, ConnectWise published an advisory to warn of “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions,” which impacts both cloud and on-premises deployments.

The company says a CVE identifier for the bug will be issued within the week, along with an official fix. In the meantime, it recommends that administrators disable the file transfer functionality in ScreenConnect to reduce the risk.

Related: Malicious Virtualizor Update Served via BGP Hijacking

Related: 23-Year-Old Sality P2P Botnet Disrupted

Related: Anthropic Warns Claude Users of Infostealer Malware Infections

Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Related Content

Vulnerabilities

Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.

Malware & Threats

The Black Basta and Bl00dy ransomware gangs have started exploiting two vulnerabilities in ConnectWise ScreenConnect.

Malware & Threats

ConnectWise ScreenConnect vulnerability tracked as CVE-2024-1709 and SlashAndGrab exploited to deliver ransomware and other malware.

Malware & Threats

Security experts describe exploitation of the CVSS 10/10 flaw as “trivial and embarrassingly easy.”

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version