Cyberattackers are exploiting a vulnerability in the popular remote access tool ScreenConnect, spreading malicious payloads across networks and establishing persistence on compromised systems. The attacks, which began in late August, involve modified ScreenConnect clients being deployed on victims’ machines via social engineering tactics.
The worm-like campaign appears to be highly targeted, with threat actors posing as tech support or other trusted individuals to gain access to users’ computers. Once inside, the malicious ScreenConnect instances spawn repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files, which are designed to perform system reconnaissance, stage payloads, and execute a PowerShell script.
The attackers also establish persistence by creating a User Run Key pointing to another VBScript file, allowing them to maintain control over the compromised systems even after the initial attack has been blocked. Furthermore, the threat actors install UltraViewer remote desktop software, which is used to continuously check for new host connections and propagate the malicious payload to other ScreenConnect endpoints.
Huntress, a cybersecurity firm that discovered the attacks, notes that the same files and operations are being executed in multiple environments, suggesting that this may be a widespread issue. The company advises administrators to apply extra scrutiny to any on-premises ScreenConnect installations within their environment, as the vulnerability is not limited to cloud deployments.
ConnectWise, the vendor behind ScreenConnect, has published an advisory warning of “an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions.” The company states that a CVE identifier for the bug will be issued within the week, along with an official fix. In the meantime, administrators are recommended to disable the file transfer functionality in ScreenConnect to reduce the risk.
In practical terms, this means that organizations using ScreenConnect should take immediate action to protect themselves from these attacks. This includes applying extra scrutiny to any on-premises installations, disabling file transfer functionality where possible, and implementing robust security measures to prevent social engineering tactics. By taking proactive steps, businesses can minimize their exposure to this vulnerability and reduce the risk of falling victim to a sophisticated cyberattack.
It’s worth noting that while ScreenConnect is primarily used for remote access support, its widespread adoption has made it an attractive target for attackers looking to spread malware across networks. As such, administrators should prioritize securing their ScreenConnect installations, along with other critical systems and tools, to prevent potential compromise.
Source: SecurityWeek — 2026-09-07