Modified ScreenConnect Clients Spread Malware to Support Operators via Worm-Like Technique
Security researchers at Huntress have identified a campaign in which tampered ConnectWise ScreenConnect clients on compromised endpoints automatically push malicious scripts to operator machines that connect to them for remote support. The attack begins through social engineering, where victims are tricked into granting remote access or installing an unauthorized ScreenConnect client, sometimes preceded by abuse of Microsoft Quick Assist. Once a Guest endpoint is infected, the modified client exploits ScreenConnect's built-in file-transfer and script-execution features to deliver a series of VBScript files to any Host operator that connects. Depending on the target environment, payloads can include user-level remote access tools, persistence mechanisms, UAC bypass, network tunneling via wstunnel, and cryptocurrency mining using XMRig. Defenders are advised to watch for ScreenConnect spawning wscript.exe, execution of numbered VBS files, and suspicious RunFiles audit entries as key indicators of compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in