Cybersecurity researchers at Huntress have identified a worm-like campaign abusing ConnectWise ScreenConnect to deploy malicious VBScript payloads and secondary tools across compromised remote access support systems.
Key Points
- Attackers utilize social engineering, phishing, and fake refund forms to install rogue ScreenConnect clients on victim machines.
- A four-stage VBScript chain profiles host systems, checks for security software, and downloads secondary payloads from Dropbox.
- Depending on system state, payloads include user-level backdoors, privilege escalation tools, or XMRig cryptocurrency miners.
- The malware exhibits worm-like behavior by propagating malicious scripts to new hosts that connect to an already infected ScreenConnect client.
- ConnectWise has acknowledged the vulnerability and recommends that administrators temporarily disable file transfer permissions to mitigate unauthorized script execution.