ZeroHour
Story · 1 source · 1 articlefirst updated ()

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain in Worm-Like Campaign

highMalwareexploited in the wildimportance 72
What's new: This is the first merged summary of this story, combining reporting from The Hacker News and SecurityWeek published 2026-09-07. Details surfaced this round: the ConnectWise advisory references a CVE identifier with a fix expected within a week and recommends disabling file transfer meanwhile; the PowerShell stage erases evidence, persists via User Run Keys, and installs UltraViewer; and the…
Merged summary · glm-5.3 · rewritten as coverage arrives

Huntress warns that rogue ScreenConnect clients installed via tech-support scams — including Quick Assist abuse, phishing MSI installers, and fake Geek Squad refund lures — run a four-stage VBScript chain delivering backdoors, UAC-bypass tooling, and an XMRig…

Huntress identified three unrelated incidents in August 2026 in which attackers used social engineering — a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form — to install rogue ScreenConnect clients. Each client repeatedly spawned wscript.exe to run four chained VBScript files (1.vbs through 4.vbs) that profiled the host, enumerated installed security products, and downloaded stage-specific payloads from Dropbox. Depending on the detected state, payloads included a user-level ScreenConnect backdoor, UAC-bypass privilege escalation tooling, or tunneling utilities bundled with an XMRig cryptocurrency miner. The PowerShell stage erased evidence, persisted via User Run Keys, and installed the UltraViewer remote desktop tool. Infected clients re-infected newly connected hosts, creating worm-like propagation across ScreenConnect sessions. ConnectWise published an advisory about a file transfer behavior issue affecting both cloud and on-premises ScreenConnect deployments, referencing a CVE identifier (not specified in either report) with a fix expected within a week; the company recommends disabling file transfer until the patch is released. Huntress recommends reimaging affected hosts.

  • Huntress identified three unrelated incidents in August 2026; SecurityWeek reports the campaign began in late August
  • Initial access used a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form
  • Rogue ScreenConnect clients repeatedly spawned wscript.exe to run four chained VBScript files (1.vbs through 4.vbs) for reconnaissance, staging, and PowerShell execution
  • The scripts profiled hosts, enumerated installed security products, and downloaded stage-specific payloads from Dropbox
  • Payload branches delivered a user-level ScreenConnect backdoor, UAC-bypass privilege escalation tooling, or tunneling utilities with an XMRig cryptocurrency miner
  • The PowerShell stage erased evidence, persisted via User Run Keys, and installed the UltraViewer remote desktop tool
  • Backdoored clients re-infected newly connected hosts, creating worm-like propagation over ScreenConnect sessions
  • ConnectWise issued an advisory on a file transfer behavior issue affecting cloud and on-premises ScreenConnect, referencing a CVE identifier (not specified in reports) with a fix expected within a week

Coverage timeline

  1. · 8d ago
    The Hacker News· 72
    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Huntress says rogue ScreenConnect clients spread a four-stage VBScript chain delivering backdoors, privilege-escalation tools, or an XMRig miner to newly connected hosts.