Skip to content

Rogue ScreenConnect Clients Spread Worm

Gbhackers Mayura Kathir September 3, 2026

A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is […]

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (1)