SECURITYWEEK reports that modified ScreenConnect clients are being used in a worm-like campaign to spread malicious payloads to connected endpoints. The attacks begin with rogue ScreenConnect instances deployed on victims’ machines via social engineering, after which the compromised clients spawn multiple Windows Script Host (wscript[.]exe) processes to run four VBScript files.
The campaign has been observed across different organisations, with attackers establishing persistence by creating a User Run Key and, in some cases, installing UltraViewer remote desktop software to facilitate ongoing access.
Huntress notes that the rogue ScreenConnect client rapidly executes the four VBScript files from the ScreenConnect temporary directory, while network telemetry shows connections from ScreenConnect to several remote IP addresses.
The scripts are used for system reconnaissance, staging payloads, and launching a PowerShell chain that erases staging evidence, attempts a UAC bypass, and reinstalls a ScreenConnect client that continuously seeks out new hosts to propagate the four-stage VBScript chain to other ScreenConnect endpoints.
ConnectWise has issued an advisory warning of an issue affecting file transfer in ScreenConnect remote access sessions; a CVE will be issued and a fix released soon, with guidance to disable file transfer in the interim.