logo

Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

ID: bb0ab04c-b525-5ccb-9891-639d15f7614f

STIX ID: report--bb0ab04c-b525-5ccb-9891-639d15f7614f

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Huntress observed a campaign abusing trojanized ConnectWise ScreenConnect clients to push a four-stage VBScript loader (1.vbs–4.vbs) to newly connected Windows systems, which spawns wscript.exe, profiles hosts, decrypts tailored payloads, and can deliver backdoors, persistence/UAC bypass, tunneling, and an XMRig cryptominer; the malicious clients propagate via ScreenConnect file-transfer and have been distributed through fake support interactions and phishing installers. Defenders are urged to hunt for ScreenConnect spawning wscript.exe, Run key indicators such as WindowsServiceHost, the listed VBS hashes and malicious infrastructure, isolate affected hosts, preserve logs/binaries, and remove unauthorized remote-management tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.