Itsecurityguru
Malicious ScreenConnect Installations Spread Like Worms
Article Content
Huntress has identified a wave of rogue ScreenConnect installations across unrelated organizations, indicating a self-propagating malware campaign. The attack begins with social engineering tactics to install modified ScreenConnect clients, which then execute a series of VBScript files (1.vbs to 4.vbs) via the Windows Script Host. These scripts profile the infected machines and can deploy additional payloads, including backdoored ScreenConnect clients and cryptocurrency miners. The malware spreads automatically to new machines during legitimate remote support sessions, posing a significant risk to IT environments. Huntress is monitoring the situation and has communicated with ConnectWise regarding the issue. Organizations are advised to scrutinize their ScreenConnect audit logs for suspicious activity. The incidents began in late August 2026, with multiple organizations affected.
Key Points: • Rogue ScreenConnect installations are spreading malware through social engineering. • The malware executes VBScript files and can self-propagate during remote support sessions. • Huntress is actively monitoring the situation and communicating with ConnectWise.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.