As cited
Copy frozen at (site build).
threat intel
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Huntress researchers identified three separate incidents leveraging compromised ConnectWise ScreenConnect clients to deploy a multi-stage VBScript worm across newly connected systems. The attack chain begins with varied initial access vectors including Quick Assist tech-support scams, phishing-delivered Microsoft Installer (MSI) files, and fraudulent installers.
Why it matters: Organizations using ScreenConnect and end users targeted by tech-support scams or phishing face the risk of worm-like propagation to networked systems; security teams should audit ScreenConnect access logs and monitor for suspicious VBScript execution in connected environments.
- Source published
- First seen by Cybersecurity Tracker