Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Modified ScreenConnect Clients Used in Worm-Like Campaign

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.

Modified ScreenConnect clients are being used in an attack campaign to spread malicious payloads to other endpoints, cybersecurity firm Huntress warns.

The worm-like attacks began in late August and start with the rogue clients being deployed on victims’ machines via social engineering.

Following the installation, the malicious ScreenConnect instances have been observed spawning repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files.

Huntress noticed the same attack pattern across different organizations: the rogue ScreenConnect clients were used to propagate their payload to other connected instances, and the attackers created a User Run Key pointing to another VBScript file, for persistence.

In an August 20 attack, a threat actor posing as tech support instructed the victim to execute the Windows’s built-in remote support tool Quick Assist, thus gaining control over the victim’s machine. The hacker then executed the five VBScript files on the system before the attack was blocked.

On the same day, Huntress observed the same VBScript files being deployed in another environment, likely as part of another phishing attack.

Advertisement. Scroll to continue reading.

“The rogue ScreenConnect client almost immediately launched the four VBScript files from the ScreenConnect temporary directory. During the course of the investigation, network telemetry also identified active connections from ScreenConnect to multiple remote IP addresses,” Huntress notes.

The attacker was also seen establishing persistence through the User Run Key, and installing the UltraViewer remote desktop software.

Huntress observed the same files and operations being executed in an August 24 attack that also started with social engineering.

The four scripts deployed by the rogue ScreenConnect clients were designed for perform system reconnaissance, stage payloads, and execute a PowerShell script.

This code executes a second PowerShell script that erases staging evidence, attempts UAC bypass, and installs and conceals a ScreenConnect client that continuously checks for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.

“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress notes.

On Thursday, ConnectWise published an advisory to warn of “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions,” which impacts both cloud and on-premises deployments.

The company says a CVE identifier for the bug will be issued within the week, along with an official fix. In the meantime, it recommends that administrators disable the file transfer functionality in ScreenConnect to reduce the risk.

Related: Malicious Virtualizor Update Served via BGP Hijacking

Related: 23-Year-Old Sality P2P Botnet Disrupted

Related: Anthropic Warns Claude Users of Infostealer Malware Infections

Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.