By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ScreenConnect Exploited to Spread VBScript Worm

Cybersecurity researchers have detailed a worm-like campaign that exploits ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. Huntress, a cybersecurity firm, reported that three distinct incidents have been observed, each employing different initial access vectors. These methods include a Quick Assist tech-support scam, a phishing attack that delivers a malicious MSI installer, and a fake software download. In all observed cases, the attackers leveraged ScreenConnect, a remote access tool, to propagate the VBScript to other machines that subsequently connected to the compromised host. The VBScript itself is designed to be self-propagating, meaning it can spread to other systems without further human intervention once it gains a foothold. The campaign's sophistication lies in its ability to leverage a legitimate remote access tool for malicious purposes, making detection more challenging. The VBScript chain involves multiple stages, with each stage executing the next, escalating the malicious activity. The initial stage of the VBScript chain is responsible for downloading and executing subsequent stages. This multi-stage approach is a common tactic used by malware authors to evade detection by security software, as each stage can be obfuscated or modified independently. The ultimate goal of this campaign appears to be the establishment of persistent access and potentially the deployment of further malicious payloads, such as ransomware or information-stealing malware. The researchers highlighted that the attackers are not targeting specific industries but rather exploiting any vulnerable ScreenConnect instance they can find. This broad targeting strategy increases the potential impact of the campaign. The use of ScreenConnect is particularly concerning because it is a widely adopted tool for remote IT support and management, meaning many organizations rely on it for their daily operations. The attackers are essentially hijacking this trusted tool to facilitate their malicious activities. The VBScript payload is designed to be highly evasive, employing techniques to avoid detection by antivirus software and other security measures. The researchers are urging organizations to ensure their ScreenConnect instances are up-to-date with the latest security patches and to implement robust security monitoring to detect any unusual activity. The campaign underscores the ongoing threat posed by attackers who leverage legitimate software and tools for malicious ends, a trend often referred to as 'living off the land' attacks. The researchers' analysis indicates that the attackers are actively refining their techniques, suggesting that this campaign may evolve further. The specific details of the VBScript's obfuscation techniques and the full chain of execution are being withheld to prevent further exploitation, but the core mechanism involves the abuse of ScreenConnect's remote execution capabilities. The campaign's worm-like nature means that once a single ScreenConnect instance is compromised and the VBScript is deployed, it can rapidly spread to other systems within a network or even across different networks if those systems have remote access capabilities enabled. This rapid propagation capability makes it a significant threat to business continuity and data security. The researchers' proactive disclosure aims to equip organizations with the knowledge to defend against this evolving threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.