Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Summary
Researchers have identified worm-like activity utilizing ConnectWise ScreenConnect to spread a malicious VBScript payload to newly connected hosts. This activity has been observed across three distinct incidents, employing varied initial access vectors such as Quick Assist scams, phishing, and fake installers.
IFF Assessment
This article details a new method of spreading malware, which represents a direct threat to the security of connected systems and defenders.
Defender Context
Defenders should be aware of this evolving threat that abuses legitimate remote management tools like ScreenConnect for malicious purposes. Monitoring for unusual VBScript activity and ensuring proper endpoint security configurations are crucial to prevent the spread of such payloads. This highlights the importance of securing not just direct access points but also the tools used for remote administration.