Cybersecurity firm Huntress is warning of a worm-like attack campaign that uses modified ScreenConnect remote-support clients to automatically spread malicious payloads from one compromised endpoint to others.
Social Engineering as the Entry Point
The attacks, which Huntress says began in late August, start when a threat actor tricks a victim into installing a rogue ScreenConnect client, often by posing as tech support. In one observed case from Aug. 20, an attacker convinced a victim to open Windows’ built-in Quick Assist remote-support tool, using that access to gain control of the machine before executing a chain of VBScript files.
How the Worm-Like Propagation Works
Once installed, the backdoored ScreenConnect client spawns repeated Windows Script Host processes to deploy a set of VBScript files that perform system reconnaissance, stage additional payloads, and launch a PowerShell script. That script in turn runs a second PowerShell payload that erases evidence of the staging process, attempts to bypass User Account Control, and quietly installs a concealed ScreenConnect client of its own. That hidden client then continuously watches for new host connections, propagating the same multi-stage script chain to every other ScreenConnect endpoint it can reach, which is what gives the campaign its worm-like behavior. Huntress also observed the attackers establishing persistence through a Windows Run registry key and installing the legitimate remote-desktop tool UltraViewer for continued access.
Huntress says it has observed the identical files and attack sequence across multiple, separate organizations, including a second environment compromised the same day as the initial Aug. 20 incident, and again in a further attack on Aug. 24 that also began with social engineering.
Vendor Guidance
Huntress says it has been in contact with ScreenConnect maker ConnectWise about the activity and, based on its current understanding of the risk, is advising administrators to apply extra scrutiny to any on-premises ScreenConnect installations in their environment, including monitoring for unexpected outbound connections and unfamiliar scheduled tasks or registry run-key entries tied to the software.

Leave a Reply