AUTO-UPDATED

Attackers spread malware through ScreenConnect file transfers

ConnectWise is addressing a critical file transfer vulnerability in its ScreenConnect remote access software that researchers warn could be exploited to spread malware across connected IT systems.

Key Points

  • ConnectWise confirmed a file transfer flaw affecting both Cloud and On-Premise ScreenConnect deployments, with an official security patch expected within the week.
  • Cybersecurity firm Huntress identified a campaign using rogue ScreenConnect clients to deploy malicious VBScripts and facilitate worm-like propagation across connected endpoints.
  • Attackers utilized the rogue instances to perform system discovery, establish persistence, and install additional payloads including cryptocurrency miners and tunneling tools.
  • Administrators are advised to immediately disable file transfer permissions within the ScreenConnect role settings to mitigate potential unauthorized activity.
  • Security teams should audit ScreenConnect logs for suspicious RunFiles entries and reimage any machines showing signs of compromise from verified, clean media.

Why it Matters

This vulnerability poses a significant risk to managed service providers and IT departments that rely on ScreenConnect for remote infrastructure management. If left unaddressed, the flaw could allow attackers to gain persistent access to sensitive networks and deploy malicious payloads across an entire organization's fleet.
Help Net Security Published by Sinisa Markovic
Read original