Malicious ScreenConnect Installations Spread Like Worms

Malicious ScreenConnect Installations Spread Like Worms

First seen 3 Sep 2026, 12:40 UTC Huntresswww.loldrivers.ioItsecurityguru 68.2

Article Content

Browse articles
ThreatCluster

Huntress has identified a wave of rogue ScreenConnect installations across unrelated organizations, indicating a self-propagating malware campaign. The attack begins with social engineering tactics to install modified ScreenConnect clients, which then execute a series of VBScript files (1.vbs to 4.vbs) via the Windows Script Host. These scripts profile the infected machines and can deploy additional payloads, including backdoored ScreenConnect clients and cryptocurrency miners. The malware spreads automatically to new machines during legitimate remote support sessions, posing a significant risk to IT environments. Huntress is monitoring the situation and has communicated with ConnectWise regarding the issue. Organizations are advised to scrutinize their ScreenConnect audit logs for suspicious activity. The incidents began in late August 2026, with multiple organizations affected.

Key Points: • Rogue ScreenConnect installations are spreading malware through social engineering. • The malware executes VBScript files and can self-propagate during remote support sessions. • Huntress is actively monitoring the situation and communicating with ConnectWise.

Timeline

2026-08-01
Initial incidents reported
Huntress flagged unusual activity across unrelated organizations, indicating rogue ScreenConnect installations.
Huntress
2026-08-15
Social engineering tactics identified
Investigations revealed that the attacks began with social engineering, tricking users into installing malicious software.
Huntress
2026-09-03
Public warning issued
Huntress published a blog post detailing the worm-like behavior of the malware and its impact on organizations.
Itsecurityguru