Modified ScreenConnect Clients Used in Worm-Like Campaign
A worm-like campaign utilizing modified ScreenConnect clients is spreading malicious payloads across networks. The attackers leverage social engineering and remote support tools to deploy a chain of VBScript files, ultimately installing UltraViewer and establishing persistence. ConnectWise has issued an advisory urging administrators to disable file transfer functionality within ScreenConnect to mitigate the risk.
A worm-like campaign is utilizing modified ScreenConnect clients to spread malicious payloads to multiple endpoints, according to cybersecurity firm Huntress. The attacks began in late August and initially involved threat actors deploying rogue ScreenConnect clients through social engineering tactics. Following installation, the malicious clients spawned repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files.
Huntress observed the same attack pattern across various organizations, with the rogue ScreenConnect clients propagating their payload to other connected instances. The attackers established persistence via the User Run Key, installing UltraViewer remote desktop software, and creating a chain of VBScript files.
On August 20th, a threat actor posing as tech support instructed a victim to execute Quick Assist, gaining control of the machine before deploying the five VBScript files. The scripts were designed for system reconnaissance, payload staging, and executing a PowerShell script. This PowerShell script then erased staging evidence, attempted UAC bypass, and installed a new ScreenConnect client that continuously checked for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.
ConnectWise published an advisory on Thursday warning of an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions, impacting both cloud and on-premises deployments. The company recommends disabling file transfer functionality in ScreenConnect to reduce the risk, and a CVE identifier will be released within the week alongside an official fix.
Related: Malicious Virtualizor Update Served via BGP Hijacking Related: 23-Year-Old Sality P2P Botnet Disrupted Related: Anthropic Warns Claude Users of Infostealer Malware Infections Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis