Modified ScreenConnect Clients Used in Worm-Like Campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign
Modified ScreenConnect clients are being abused in a worm-like campaign that spreads malicious VBScript and PowerShell payloads across connected endpoints after initial social-engineering access. Huntress and ConnectWise warn that the issue affects ScreenConnect deployments and recommend disabling file transfer while an official fix is prepared. #ScreenConnect #ConnectWise #Huntress #QuickAssist #UltraViewer

Keypoints

  • Rogue ScreenConnect clients are being installed through social engineering.
  • The malware spawns wscript.exe to run multiple VBScript files.
  • Attackers use persistence through a User Run Key.
  • The payload stages reconnaissance, PowerShell execution, and cleanup actions.
  • ConnectWise advises disabling file transfer in ScreenConnect until a fix is released.

Read More: https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/