www.securityweek.com 7 Sept 2026, 11:45 UTC

Worm-Like ScreenConnect Attack Spreads Payloads Across Endpoints

Worm-Like ScreenConnect Attack Spreads Payloads Across Endpoints
CyberSIXT Evidence Panel Source marked as original reporting

SECURITYWEEK reports that modified ScreenConnect clients are being used in a worm-like campaign to spread malicious payloads to connected endpoints. The attacks begin with rogue ScreenConnect instances deployed on victims’ machines via social engineering, after which the compromised clients spawn multiple Windows Script Host (wscript[.]exe) processes to run four VBScript files.

The campaign has been observed across different organisations, with attackers establishing persistence by creating a User Run Key and, in some cases, installing UltraViewer remote desktop software to facilitate ongoing access.

Huntress notes that the rogue ScreenConnect client rapidly executes the four VBScript files from the ScreenConnect temporary directory, while network telemetry shows connections from ScreenConnect to several remote IP addresses.

The scripts are used for system reconnaissance, staging payloads, and launching a PowerShell chain that erases staging evidence, attempts a UAC bypass, and reinstalls a ScreenConnect client that continuously seeks out new hosts to propagate the four-stage VBScript chain to other ScreenConnect endpoints.

ConnectWise has issued an advisory warning of an issue affecting file transfer in ScreenConnect remote access sessions; a CVE will be issued and a fix released soon, with guidance to disable file transfer in the interim.

View full article

Article by CyberSIXT