ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Modified ScreenConnect Clients Used in Worm-Like Campaign

highExploit / PoC exploited in the wildimportance 66
AI summary · glm-5.3-flash

Huntress warns of worm-like attacks using modified ScreenConnect clients to spread VBScript payloads; ConnectWise issued an advisory.

Campaigns starting in late August use social engineering, including Quick Assist abuse, to install rogue ScreenConnect clients that spawn wscript.exe and deploy four VBScript files for reconnaissance, staging, and PowerShell execution. The attackers persist via User Run Keys, attempt UAC bypass, install UltraViewer, and propagate the VBScript chain to other connected ScreenConnect endpoints. ConnectWise published an advisory about a file transfer behavior issue affecting cloud and on-premises ScreenConnect, with a CVE identifier and fix expected within a week; it recommends disabling file transfer meanwhile.

  • Rogue ScreenConnect clients spawn repeated wscript.exe processes to run four VBScript files
  • PowerShell stage erases evidence, attempts UAC bypass, and installs hidden ScreenConnect client
  • Persistence via User Run Keys; UltraViewer remote desktop installed
  • Attacks began with tech-support social engineering and Quick Assist abuse
  • ConnectWise advisory: disable file transfer until CVE and patch are released
Full article447 words · extracted from securityweek.com · click to collapse

Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns.

The worm-like attacks began in late August and start with the rogue clients being deployed on victims’ machines via social engineering.

Following the installation, the malicious ScreenConnect instances have been observed spawning repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files.

Huntress noticed the same attack pattern across different organizations: the rogue ScreenConnect clients were used to propagate their payload to other connected instances, and the attackers created a User Run Key pointing to another VBScript file, for persistence.

In an August 20 attack, a threat actor posing as tech support instructed the victim to execute the Windows’s built-in remote support tool Quick Assist, thus gaining control over the victim’s machine. The hacker then executed the five VBScript files on the system before the attack was blocked.

On the same day, Huntress observed the same VBScript files being deployed in another environment, likely as part of another phishing attack.

Advertisement. Scroll to continue reading.

“The rogue ScreenConnect client almost immediately launched the four VBScript files from the ScreenConnect temporary directory. During the course of the investigation, network telemetry also identified active connections from ScreenConnect to multiple remote IP addresses,” Huntress notes.

The attacker was also seen establishing persistence through the User Run Key, and installing the UltraViewer remote desktop software.

Huntress observed the same files and operations being executed in an August 24 attack that also started with social engineering.

The four scripts deployed by the rogue ScreenConnect clients were designed for perform system reconnaissance, stage payloads, and execute a PowerShell script.

This code executes a second PowerShell script that erases staging evidence, attempts UAC bypass, and installs and conceals a ScreenConnect client that continuously checks for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.

“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress notes.

On Thursday, ConnectWise published an advisory to warn of “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions,” which impacts both cloud and on-premises deployments.

The company says a CVE identifier for the bug will be issued within the week, along with an official fix. In the meantime, it recommends that administrators disable the file transfer functionality in ScreenConnect to reduce the risk.

Related: Malicious Virtualizor Update Served via BGP Hijacking

Related: 23-Year-Old Sality P2P Botnet Disrupted

Related: Anthropic Warns Claude Users of Infostealer Malware Infections

Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/