Hackers Weaponize ScreenConnect to Spread Worm-Like Malware Across Windows Systems
ID: 8ad8fb54-35b9-5c56-ab69-7cf437b2bb43
STIX ID: report--8ad8fb54-35b9-5c56-ab69-7cf437b2bb43
Feed Name: cybersecurityNews.com
Huntress reports a coordinated campaign where attackers use compromised or modified ScreenConnect remote-support clients to transfer and execute a four-stage VBScript loader across Windows hosts, enabling lateral propagation, persistence, privilege escalation, tunneling and cryptocurrency mining; the report details infection vectors (tech support scams, phishing), mitigation advice (reimage, audit ScreenConnect, monitor script/PowerShell activity) and provides extensive IoCs (filenames, SHA256s, IPs, domains, registry keys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
