AUTO-UPDATED

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers at Huntress have identified a worm-like campaign abusing ConnectWise ScreenConnect to deploy malicious VBScript payloads and secondary tools across compromised remote access support systems.

Key Points

  • Attackers utilize social engineering, phishing, and fake refund forms to install rogue ScreenConnect clients on victim machines.
  • A four-stage VBScript chain profiles host systems, checks for security software, and downloads secondary payloads from Dropbox.
  • Depending on system state, payloads include user-level backdoors, privilege escalation tools, or XMRig cryptocurrency miners.
  • The malware exhibits worm-like behavior by propagating malicious scripts to new hosts that connect to an already infected ScreenConnect client.
  • ConnectWise has acknowledged the vulnerability and recommends that administrators temporarily disable file transfer permissions to mitigate unauthorized script execution.

Why it Matters

This campaign highlights the significant security risks posed by compromised remote monitoring and management tools, which can be weaponized to facilitate lateral movement across networks. Organizations should prioritize disabling unnecessary file transfer capabilities and consider re-imaging systems that have been exposed to these malicious scripts.
Internet Published by info@thehackernews.com (The Hacker News)
Read original