Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Invisible Unicode Characters Evade Phishing Detection in Millions of Emails
September 4, 2026
Hackers Exploit AI Models Claude, Qwen, DeepSeek for Cyberattacks
September 4, 2026
Microsoft Exchange Online Outage Delays External Emails
September 4, 2026
Home/Threats/Critical ConnectWise ScreenConnect Vulnerabilities Let Attackers Spread Malware
Threats

Critical ConnectWise ScreenConnect Vulnerabilities Let Attackers Spread Malware

Key Takeaways Attackers are exploiting ConnectWise ScreenConnect installations, turning legitimate remote support tools into malware distribution mechanisms. The threat leverages social engineering...

David kimber
David kimber
September 3, 2026 4 Min Read
10 0

Key Takeaways

  • Attackers are exploiting ConnectWise ScreenConnect installations, turning legitimate remote support tools into malware distribution mechanisms.
  • The threat leverages social engineering to gain initial access, then uses the compromised ScreenConnect client to spread payloads to other connected Windows systems.
  • This campaign is notable for its worm-like propagation, where an infected client can automatically push malware to newly connected machines without requiring further user interaction.
  • The activity was first identified in late August by Huntress researchers, indicating a coordinated operation rather than isolated incidents.
  • Organizations must verify the legitimacy of all ScreenConnect installations and implement robust security measures to prevent initial compromise and subsequent lateral movement.

Attackers Weaponize ScreenConnect for Worm-Like Malware Spread

Cybersecurity analysts have uncovered a sophisticated campaign where threat actors are transforming legitimate remote support software, specifically ConnectWise ScreenConnect, into a potent tool for spreading malware across Windows environments. This alarming development allows compromised remote-access clients to automatically push malicious payloads to connected systems, enabling a worm-like propagation that bypasses traditional initial compromise methods for each new victim.

Table Of Content

  • Key Takeaways
  • Attackers Weaponize ScreenConnect for Worm-Like Malware Spread
  • The Infection Chain: From Social Engineering to Systemic Compromise
  • Weaponized ScreenConnect Clients and Worm-like Propagation
  • Social Engineering Opens the Door
  • What You Should Do

The Infection Chain: From Social Engineering to Systemic Compromise

The campaign initiates through various social engineering tactics. These include deceptive technical support interactions, targeted phishing emails, and fraudulent refund inquiries. Victims are tricked into either granting remote access directly or installing an unauthorized ScreenConnect client on their devices. This initial foothold then allows attackers to leverage the trusted remote administration tool as a covert delivery channel.

This method circumvents software vulnerabilities by exploiting trust and standard support workflows. Researchers at Huntress first identified this pattern in late August, observing it across multiple, unrelated organizations during critical incidents. The consistent nature of these attacks suggests a well-coordinated operation rather than isolated incidents of abuse.

Once established, the malware profiles the compromised host, attempting to evade detection by certain security tools. It then establishes persistence to ensure re-execution after system restarts and can deploy additional malicious tools. As Huntress said in a report shared with Cyber Security News (CSN), the operation can escalate privileges, weaken Windows security defenses, tunnel network traffic, and even deploy cryptocurrency miners, depending on its capabilities.

The challenge for defenders lies in the fact that these malicious remote sessions often appear legitimate, blending seamlessly into routine administrative activities. This makes detection difficult until unexpected script executions are identified on affected endpoints.

Weaponized ScreenConnect Clients and Worm-like Propagation

The compromised ScreenConnect clients are configured to repeatedly launch Windows Script Host, executing a four-stage script chain. The initial stages perform system checks and prepare encrypted follow-on content. Subsequent stages then select and deploy payloads based on the reconnaissance results. This highlights the dangers of unauthorized remote-access deployments, which demand the same level of urgency as conventional malware infections.

A particularly concerning aspect of this campaign involves how modified clients handle new host sessions. When a new system connects, the compromised client packages the staged scripts using ScreenConnect’s file-transfer feature and marks them for execution on the newly connected machine. This transforms ordinary remote connections into an infection vector, giving the activity its distinctive worm-like characteristics. The malicious code tracks connection identifiers to prevent redundant payload delivery during an active session. However, these records are cleared upon disconnection, meaning that reconnecting the same system could trigger the entire delivery chain again, significantly expanding the attacker’s reach.

One branch of the attack chain installs a stealthy remote-access client with elevated privileges, while another deploys tunneling software and cryptocurrency mining tools. This reflects a broader trend of abusing remote-management tools for persistent, hands-on control, as observed in recent ScreenConnect abuse reports. While the tool itself is not malicious, an attacker-controlled installation provides a durable foothold within a network.

Social Engineering Opens the Door

These incidents underscore the critical impact of social engineering, where a convincing phone call, message, or download can lead directly to endpoint compromise. In one instance, a victim used Windows Quick Assist following a technical support scam. In another, a phishing lure led to the download and execution of a malicious installer. Similar tactics have been observed in Teams Quick Assist attacks, where attackers impersonate support staff to gain interactive access to systems.

What You Should Do

  • Isolate and Reimage Affected Hosts: Immediately isolate any suspected or confirmed compromised systems. Reimage these hosts from known-good media or perform a clean operating system installation to ensure all malicious components are removed.
  • Audit On-Premises ScreenConnect Deployments: Thoroughly review all on-premises ScreenConnect installations to verify their authorization and integrity. Do not assume a remote-support client is legitimate simply because it bears a familiar name.
  • Monitor Audit Logs for Suspicious Activity: Pay close attention to server audit-log entries that show remote file-execution actions from a guest process, particularly if they reference the staged scripts (e.g., 1.vbs, 2.vbs, 3.vbs, 4.vbs).
  • Investigate Unusual Script Host Activity: Be vigilant for unusual Windows Script Host (wscript.exe or cscript.exe) or PowerShell activity linked to ScreenConnect sessions. Attackers may change filenames to evade detection.
  • Educate Users on Social Engineering: Conduct regular training for users on identifying and reporting social engineering attempts, including unsolicited calls, pop-ups, or search results prompting remote access or software installation. Emphasize never sharing remote-control codes or running support software from unverified sources.
  • Restrict Remote Management Software Installation: Implement policies to restrict the installation of remote-management software to authorized personnel and approved channels only.
  • Review and Patch Remote Control Infrastructure: Ensure all remote-control infrastructure, including ConnectWise ScreenConnect, is promptly reviewed and patched against known vulnerabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarePatchphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Phantom Deal Hackers Impersonate Execs, Use Fake NDAs to Steal Wire Transfers

Next Post

LLMjacking Attack Steals Paid AI Model Access via Leaked AWS IAM Key

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Archer Flaws Let Attackers Run Remote Code
September 4, 2026
Plex Patches Critical Vulnerabilities in Media Server
September 4, 2026
Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers
September 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us