Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns.
The worm-like attacks began in late August and start with the rogue clients being deployed on victims’ machines via social engineering.
Following the installation, the malicious ScreenConnect instances have been observed spawning repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files.
Huntress noticed the same attack pattern across different organizations: the rogue ScreenConnect clients were used to propagate their payload to other connected instances, and the attackers created a User Run Key pointing to another VBScript file, for persistence.
In an August 20 attack, a threat actor posing as tech support instructed the victim to execute the Windows’s built-in remote support tool Quick Assist, thus gaining control over the victim’s machine. The hacker then executed the five VBScript files on the system before the attack was blocked.
On the same day, Huntress observed the same VBScript files being deployed in another environment, likely as part of another phishing attack.
“The rogue ScreenConnect client almost immediately launched the four VBScript files from the ScreenConnect temporary directory. During the course of the investigation, network telemetry also identified active connections from ScreenConnect to multiple remote IP addresses,” Huntress notes.
The attacker was also seen establishing persistence through the User Run Key, and installing the UltraViewer remote desktop software.
Huntress observed the same files and operations being executed in an August 24 attack that also started with social engineering.
The four scripts deployed by the rogue ScreenConnect clients were designed for perform system reconnaissance, stage payloads, and execute a PowerShell script.
This code executes a second PowerShell script that erases staging evidence, attempts UAC bypass, and installs and conceals a ScreenConnect client that continuously checks for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.
“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress notes.
On Thursday, ConnectWise published an advisory to warn of “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions,” which impacts both cloud and on-premises deployments.
The company says a CVE identifier for the bug will be issued within the week, along with an official fix. In the meantime, it recommends that administrators disable the file transfer functionality in ScreenConnect to reduce the risk.
Related: Malicious Virtualizor Update Served via BGP Hijacking
Related: 23-Year-Old Sality P2P Botnet Disrupted
Related: Anthropic Warns Claude Users of Infostealer Malware Infections
Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis
