CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5622

As cited

Copy frozen at (site build).

threat intel

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

Huntress researchers discovered rogue ScreenConnect clients across multiple customer environments spawning Windows Script Host processes to execute a series of four VBScript files, suggesting coordinated or worm-like propagation activity. The pattern indicates attackers have established persistent remote access mechanisms and are using legitimate remote management software as a delivery vehicle for malicious scripts.

Why it matters: Organizations using ScreenConnect face immediate exposure if rogue instances are active on their networks; practitioners should audit running ScreenConnect processes and check Windows Script Host execution logs for unauthorized VBScript activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

Huntress researchers discovered rogue ScreenConnect clients across multiple customer environments spawning Windows Script Host processes to execute a series of four VBScript files, suggesting coordinated or worm-like propagation activity. The pattern indicates attackers have established persistent remote access mechanisms and are using legitimate remote management software as a delivery vehicle for malicious scripts.

Why it matters: Organizations using ScreenConnect face immediate exposure if rogue instances are active on their networks; practitioners should audit running ScreenConnect processes and check Windows Script Host execution logs for unauthorized VBScript activity.

VendorsMicrosoftConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary