Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Summary

Researchers have identified worm-like activity utilizing ConnectWise ScreenConnect to spread a malicious VBScript payload to newly connected hosts. This activity has been observed across three distinct incidents, employing varied initial access vectors such as Quick Assist scams, phishing, and fake installers.

IFF Assessment

FOE

This article details a new method of spreading malware, which represents a direct threat to the security of connected systems and defenders.

Defender Context

Defenders should be aware of this evolving threat that abuses legitimate remote management tools like ScreenConnect for malicious purposes. Monitoring for unusual VBScript activity and ensuring proper endpoint security configurations are crucial to prevent the spread of such payloads. This highlights the importance of securing not just direct access points but also the tools used for remote administration.

Read Full Story →