A sophisticated cyber threat campaign has been uncovered, exploiting a vulnerability in ScreenConnect, a popular remote desktop access tool used by organizations worldwide. The attackers are using a clever four-stage VBScript chain to compromise newly connected hosts, spreading malware and potentially leading to full network breaches.
The attack vector relies on an initial infection, which is then leveraged to execute a VBScript payload on the compromised host. This script creates a malicious ScreenConnect client that connects back to the attacker’s server, allowing them to remotely access the vulnerable system. The attackers are then able to spread the malware further by exploiting vulnerabilities in the remote desktop protocol (RDP) and other connected systems.
The vulnerability is not unique to ScreenConnect itself but rather lies in how it handles connections from external hosts. When a new client connects, it creates a temporary directory on the server-side to store session data. Attackers are exploiting this feature to execute their VBScript payload, which then spreads to other connected systems. The attackers’ use of VBScript also allows them to avoid detection by traditional antivirus solutions.
The impact of this attack is significant, as ScreenConnect is widely used across various industries. Organizations that rely on the tool for remote access should take immediate action to secure their networks. This includes ensuring all clients and servers are updated with the latest patches, regularly monitoring system logs for suspicious activity, and implementing robust security measures such as intrusion detection systems.
The attackers’ use of a four-stage VBScript chain highlights the sophistication of modern cyber threats. The initial infection vector may not be immediately apparent, making it challenging for organizations to detect and contain the breach. This serves as a reminder that cybersecurity teams must stay vigilant and proactive in their threat hunting efforts.
To mitigate this risk, organizations should prioritize regular system updates, implement robust security measures such as network segmentation, and conduct thorough vulnerability assessments. Furthermore, they should educate employees on the risks associated with remote desktop access tools like ScreenConnect and ensure they follow best practices for secure use.
Source: The Hacker News — 2026-09-07