Modified ScreenConnect Clients Used in Worm-Like Campaign

Worm-Like Attacks Spread Malicious Payloads via Modified ScreenConnect Clients

A sophisticated attack campaign has been underway since late August, using modified ScreenConnect clients to spread malicious payloads to other endpoints. The worm-like attacks begin with social engineering tactics that trick victims into installing rogue clients on their machines. Once installed, these malicious instances of ScreenConnect spawn repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files, designed for system reconnaissance, payload staging, and PowerShell execution.

The attackers have been observed using the same attack pattern across different organizations, leveraging the modified ScreenConnect clients to propagate their payload to other connected instances. In some cases, they created a User Run Key pointing to another VBScript file, ensuring persistence on compromised systems. This approach allows the attackers to maintain control over infected machines even after initial exploitation.

The malicious ScreenConnect clients have also been linked to the deployment of UltraViewer remote desktop software and the creation of active connections from ScreenConnect to multiple remote IP addresses. In one notable incident, a threat actor posing as tech support instructed a victim to execute Windows’s built-in remote support tool Quick Assist, thereby gaining control over the machine.

In response to these findings, cybersecurity firm Huntress has warned administrators to apply extra scrutiny to any on-premises ScreenConnect installations within their environment. ConnectWise has also published an advisory regarding “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions,” impacting both cloud and on-premises deployments.

In the meantime, administrators are advised to disable the file transfer functionality in ScreenConnect to reduce the risk of exploitation. It’s essential for organizations to stay vigilant, regularly monitor their systems for suspicious activity, and maintain up-to-date software and security measures to prevent such attacks from spreading.

For those using ScreenConnect, it’s crucial to verify the authenticity of any client installations and ensure that all systems are running with the latest security patches. Regularly reviewing system logs and monitoring network activity will also help detect potential threats early on. By taking these precautions, organizations can minimize their exposure to this type of attack and maintain a secure environment for their users.


Source: SecurityWeek — 2026-09-07