ConnectWise is addressing a critical file transfer vulnerability in its ScreenConnect remote access software that researchers warn could be exploited to spread malware across connected IT systems.
Key Points
- ConnectWise confirmed a file transfer flaw affecting both Cloud and On-Premise ScreenConnect deployments, with an official security patch expected within the week.
- Cybersecurity firm Huntress identified a campaign using rogue ScreenConnect clients to deploy malicious VBScripts and facilitate worm-like propagation across connected endpoints.
- Attackers utilized the rogue instances to perform system discovery, establish persistence, and install additional payloads including cryptocurrency miners and tunneling tools.
- Administrators are advised to immediately disable file transfer permissions within the ScreenConnect role settings to mitigate potential unauthorized activity.
- Security teams should audit ScreenConnect logs for suspicious RunFiles entries and reimage any machines showing signs of compromise from verified, clean media.