Modified ScreenConnect clients are being abused in a worm-like campaign that spreads malicious VBScript and PowerShell payloads across connected endpoints after initial social-engineering access. Huntress and ConnectWise warn that the issue affects ScreenConnect deployments and recommend disabling file transfer while an official fix is prepared. #ScreenConnect #ConnectWise #Huntress #QuickAssist #UltraViewer
Keypoints
- Rogue ScreenConnect clients are being installed through social engineering.
- The malware spawns wscript.exe to run multiple VBScript files.
- Attackers use persistence through a User Run Key.
- The payload stages reconnaissance, PowerShell execution, and cleanup actions.
- ConnectWise advises disabling file transfer in ScreenConnect until a fix is released.
Read More: https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/