Rogue ScreenConnect clients spread worm-like VBScript attacks

Modified ScreenConnect clients, deployed via social engineering, run VBScript chains through wscript.exe and propagate payloads to other endpoints.

Security firm Huntress reported that modified ScreenConnect remote-access clients have been used in a worm-like campaign that began in late August. The intrusions start with social engineering to install a rogue ScreenConnect instance, which then spawns repeated wscript.exe processes to run VBScript files and push the payload to other connected hosts.

Investigators documented repeated behavior across multiple organizations. In most cases the rogue client launched four VBScript files from the ScreenConnect temporary directory. In one August 20 incident, an actor posing as technical support instructed a victim to run Windows Quick Assist, obtained remote control, and executed five VBScript files before defenders interrupted the activity. Huntress observed the same set of scripts appear in a separate environment the same day.

The deployed scripts perform system reconnaissance, stage additional payloads and invoke PowerShell. The PowerShell sequence executes a follow-up script that removes staging artifacts, attempts to bypass User Account Control, and installs a concealed ScreenConnect client. That hidden client repeatedly checks for new host connections and is used to copy the four-stage VBScript chain to other ScreenConnect endpoints. Network telemetry collected during investigations showed active ScreenConnect connections to multiple remote IP addresses.

Attackers also created persistence by adding a Run key in the registry that points to a VBScript file and by installing third-party remote-access software. Huntress recorded an instance where UltraViewer was installed after the rogue ScreenConnect client appeared on a machine. The firm described the pattern as lateral propagation through connected ScreenConnect instances.

ConnectWise published an advisory stating an issue affects file transfer behavior in ScreenConnect Remote Access Support and Access sessions for both cloud and on-premises deployments. The advisory says a CVE identifier and an official fix will be provided within the week and recommends administrators disable file transfer until a patch is available.

Huntress recommended that organizations review active ScreenConnect sessions, disable file transfer where possible, monitor for unexpected ScreenConnect child processes and unusual registry Run keys, and investigate any remote desktop software installs following remote-support interactions. The firm also advised extra scrutiny of on-premises ScreenConnect installations based on its conversations with the vendor.

Articles by this author