Compromised ScreenConnect Clients Deploy VBScript Malware Across Windows Networks
Security researchers have uncovered a new threat campaign that hijacks legitimate ScreenConnect remote‑access clients to automatically distribute a multi‑stage VBScript malware chain to Windows computers that connect to infected hosts.
ScreenConnect, now marketed as ConnectWise Control, is a widely used remote support and management platform that allows technicians to establish interactive sessions with client machines. The utility’s popularity makes it an attractive vector for attackers who can replace or modify the client binaries without the end‑user’s knowledge.
In the observed attacks, the altered client initiates a silent download of a VBScript payload the moment a Windows endpoint establishes a connection. The script runs under the privileges of the logged‑in user, leverages Windows Script Host to execute further code, and often drops additional components that provide back‑door access, data‑stealing capabilities, or the ability to spread laterally.
Technical analysis indicates the malware chain is deliberately modular. The initial script performs environment checks, writes additional scripts to the system directory, and contacts external servers to retrieve more sophisticated payloads. By chaining stages, the attackers can evade simple signature‑based detection and adapt the final payload to the target’s configuration.
Because the malicious client operates whenever a legitimate remote session is opened, any Windows device that connects to an infected host can become a victim. This amplifies the risk in corporate environments where remote support tools are frequently used across multiple departments, potentially enabling rapid intra‑network propagation.
Defenders are advised to monitor for anomalous ScreenConnect traffic, verify the integrity of client executables using vendor‑provided hashes, and enforce application whitelisting policies that block unauthorized scripts. Updating to the latest version of ConnectWise Control and applying strict network segmentation for remote‑access services can also limit exposure.
ConnectWise has acknowledged the issue and is working with security partners to issue patches that restore the client’s integrity checks. Several endpoint‑protection vendors have added detections for the specific VBScript patterns identified in the campaign.
The incident reflects a broader trend where threat actors weaponize legitimate remote‑administration tools, a practice that surged during the pandemic‑driven shift to remote work. As organizations continue to rely on such software, the attack surface expands, underscoring the need for vigilant supply‑chain security and regular audits of remote‑access configurations.
Researchers continue to track the campaign’s infrastructure and are attempting to attribute the activity to known threat groups. While attribution remains tentative, the sophistication of the multi‑stage payload suggests a well‑resourced adversary with experience in stealthy malware deployment.
Comments (0)
Be the first to comment.
Join the discussion