Itsecurityguru
Rogue ScreenConnect Clients Spread Malware Like a Worm
Article Content
Huntress has reported a wave of rogue ScreenConnect installations that spread malware across Windows systems without further action from victims or attackers. This self-propagating attack chain, resembling a worm, begins with social engineering tactics, such as fake tech-support calls. Once installed, the rogue clients execute a series of four VBScript files (1.vbs to 4.vbs) via the Windows Script Host, allowing them to profile the infected machine and deploy additional payloads. The modified ScreenConnect clients can automatically transfer these scripts to newly connected systems, facilitating further infections. Huntress has observed this behavior across multiple unrelated organizations, indicating a widespread issue. The campaign is ongoing, and Huntress is in communication with ConnectWise regarding the situation.
Key Points: • Rogue ScreenConnect clients are spreading malware autonomously across Windows systems. • The attack begins with social engineering tactics, including fake tech-support interactions. • Infected clients can propagate malware to newly connected systems without additional user action.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.