Description

A malicious campaign is abusing rogue ConnectWise ScreenConnect clients to spread malware across Windows systems connected to compromised remote-access environments. According to Huntress, attackers have used social-engineering methods such as fake Quick Assist support sessions, phishing emails carrying malicious ScreenConnect installers, and fraudulent technical-support or refund pages to convince victims to install attacker-controlled clients. Once installed, the modified ScreenConnect client can do more than provide remote access. It can automatically transfer and execute a four-stage VBScript malware chain on newly connected Windows systems, effectively turning ScreenConnect into a propagation mechanism. The infection begins with several VBScript files that profile the victim's system and check for security products, existing ScreenConnect installations, and available memory. The scripts then retrieve an encoded configuration and use it to select an encrypted payload suitable for the infected environment. A later PowerShell stage decrypts the payload, extracts additional files, and executes them while attempting to remove evidence of the infection. Researchers identified multiple payload outcomes, including a ScreenConnect backdoor, persistence and privilege-escalation tools, tunneling software, and cryptocurrency-mining components. The malware also contains techniques designed to weaken security controls, including attempts to disable AMSI scanning and add locations to Microsoft Defender exclusions. The most concerning feature is the ability of the modified ScreenConnect client to identify newly connected hosts and transfer the malicious scripts to them through ScreenConnect's file-transfer functionality. The infected system can therefore become another propagation point when additional hosts connect. Organizations should investigate unauthorized ScreenConnect installations, monitor for ScreenConnect processes spawning wscript.exe, and look for suspicious VBScript and PowerShell activity. Security teams should also review ScreenConnect audit logs, isolate affected endpoints, preserve forensic evidence, remove unauthorized remote-management tools, and rotate credentials used from compromised systems. Because the campaign relies heavily on social engineering, users should verify remote-support requests and install ScreenConnect software only from trusted sources.