Malicious VBScript Chain Exploits ScreenConnect for Network Propagation
Rogue ScreenConnect clients deploy a four-stage VBScript chain to compromise newly connected hosts, enabling worm-like propagation and delivering payloads including cryptocurrency miners and backdoors. The attack leverages social engineering and phishing to install malicious Remote Access Tools (RATs) that exploit system vulnerabilities and evade detection.
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
*** END OF TRANSMISSION ***