Fast Facts
- Cybercriminals exploit ConnectWise ScreenConnect via social engineering, phishing, and fake forms to deploy multi-stage VBScript payloads that can establish remote backdoors or mine cryptocurrency.
- The malware propagates worm-like by re-infecting connected hosts through repeated ScreenConnect sessions, executing scripts that disable security tools and escalate privileges.
- Affected systems risk persistent backdoors, credential theft, privilege escalation, and malicious payload delivery, with ongoing threats due to inherent file transfer vulnerabilities in ScreenConnect.
Threat Overview, Techniques, and Targets
Cybersecurity researchers have revealed a new worm-like activity abusing ConnectWise ScreenConnect. The activity involves a four-stage VBScript chain used to infect systems connected to ScreenConnect. Attackers use different methods to gain initial access, including tech-support scams, phishing with MSI installers, and fake refund forms. Once connected, the malicious scripts are deployed from a command-and-control server.
The attack sequence starts with a VBS script that checks the host system’s resources and security status. Next, it downloads additional payloads from Dropbox. These payloads vary and include backdoors, privilege escalation tools, tunneling utilities, or a cryptocurrency miner. The scripts are run using “wscript.exe” and result in persistent malicious activity. When a host connects to an infected ScreenConnect client, the same chain of scripts runs, turning the host into a spread mechanism for the malware.
Targets are mainly systems with ScreenConnect installed or connected via malicious clients. The infection can also escalate privileges or disable security tools. The chain can infect multiple hosts through new ScreenConnect connections, creating a worm-like spread pattern.
Impact, Security, and Remediation Guidance
The malware chain can cause serious damage by installing backdoors, facilitating privilege escalation, and disabling security features. Some payloads also launch cryptocurrency mining operations, which abuse system resources. The infection may also enable further attacks or data theft.
This activity has serious security implications. Organizations using ScreenConnect should be aware that these attacks can lead to persistent infections and network compromise. As a result, affected systems could become part of a larger malicious network.
To remediate this threat, organizations should consider re-imaging infected hosts or performing a clean OS install. If security patches are not available, victims should consult the vendor or relevant security authorities for remediation guidance. Meanwhile, users are advised to disable file transfer features in ScreenConnect temporarily. Instructions are available from the vendor’s advisory to mitigate the risk until security updates are released.
Discover More Technology Insights
Explore the future of technology with our detailed insights on Artificial Intelligence.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
