Modified ScreenConnect Clients Used in Worm-Like Campaign

Summary

Attackers are using modified ScreenConnect client instances to distribute and execute malicious payloads on newly connected devices. This approach creates a worm-like campaign, where compromised clients actively spread further infections.

IFF Assessment

FOE

The identified attack method leverages a legitimate tool for malicious purposes, enabling the spread of malware in a self-propagating manner, which poses a significant threat to defenders.

Defender Context

Defenders should be aware of campaigns that exploit remote access tools like ScreenConnect. Monitoring for unusual network activity and unauthorized payload execution originating from these clients is crucial. Implementing strict access controls and regular patching for remote access software can mitigate such risks.

Read Full Story →