Rogue ScreenConnect Clients Spread Malware Like a Worm

Rogue ScreenConnect Clients Spread Malware Like a Worm

First seen 3 Sep 2026, 12:40 UTC Huntresswww.loldrivers.ioItsecurityguruGbhackersCybersecuritynews+3 71.0

Article Content

Browse articles
ThreatCluster

Huntress has reported a wave of rogue ScreenConnect installations that spread malware across Windows systems without further action from victims or attackers. This self-propagating attack chain, resembling a worm, begins with social engineering tactics, such as fake tech-support calls. Once installed, the rogue clients execute a series of four VBScript files (1.vbs to 4.vbs) via the Windows Script Host, allowing them to profile the infected machine and deploy additional payloads. The modified ScreenConnect clients can automatically transfer these scripts to newly connected systems, facilitating further infections. Huntress has observed this behavior across multiple unrelated organizations, indicating a widespread issue. The campaign is ongoing, and Huntress is in communication with ConnectWise regarding the situation.

Key Points: • Rogue ScreenConnect clients are spreading malware autonomously across Windows systems. • The attack begins with social engineering tactics, including fake tech-support interactions. • Infected clients can propagate malware to newly connected systems without additional user action.

Ask AI about this cluster

Timeline

2026-08-31
Huntress detects unusual activity
Huntress's SOC flagged a pattern of rogue ScreenConnect installations across unrelated organizations.
Huntress
2026-09-03
Public warning issued
Huntress published a blog post detailing the self-propagating malware campaign and its methods.
Huntress
2026-09-03
Media coverage expands
Multiple cybersecurity outlets report on the Huntress findings, highlighting the worm-like behavior of the malware.
Itsecurityguru