Modified ScreenConnect Clients Used in Worm-Like Campaign
Summary
Attackers are using modified ScreenConnect client instances to distribute and execute malicious payloads on newly connected devices. This approach creates a worm-like campaign, where compromised clients actively spread further infections.
IFF Assessment
FOE
The identified attack method leverages a legitimate tool for malicious purposes, enabling the spread of malware in a self-propagating manner, which poses a significant threat to defenders.
Defender Context
Defenders should be aware of campaigns that exploit remote access tools like ScreenConnect. Monitoring for unusual network activity and unauthorized payload execution originating from these clients is crucial. Implementing strict access controls and regular patching for remote access software can mitigate such risks.