Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers
ConnectWise confirmed a file transfer flaw in ScreenConnect Remote Access Support and Access sessions affecting both Cloud and On-Premise deployments, with a CVE and official fix expected within the week. Huntress found rogue ScreenConnect clients used in social-engineering attacks to spread VBScript payloads, persist on systems, and enable worm-like propagation across newly connected machines. #ScreenConnect #ConnectWise #Huntress #WindowsScriptHost

Keypoints

  • ScreenConnect has a file transfer flaw affecting Cloud and On-Premise deployments.
  • ConnectWise said a CVE and official fix will be issued within the week.
  • Huntress linked rogue ScreenConnect instances to social-engineering-based compromise.
  • The attack used VBScript files and Windows registry persistence to spread malware-like activity.
  • ConnectWise recommends disabling file transfers, and Huntress advises checking audit logs and reimaging impacted machines.

Read More: https://www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/