$ techbeacon▋
Phishing

Malware Exploits ConnectWise ScreenConnect to Propagate VBScript Worm Across Networks

Malware Exploits ConnectWise ScreenConnect to Propagate VBScript Worm Across Networks

Security analysts have uncovered a new worm‑like campaign that leverages ConnectWise ScreenConnect, a remote support tool, to spread a malicious Visual Basic Script (VBScript) payload to any system that subsequently connects to an infected host. The technique, which allows the script to cascade across multiple endpoints, was identified by researchers at Huntress after tracing three separate, unrelated incidents that shared the same infection pattern.

According to the findings, the malicious code embeds itself within the ScreenConnect client configuration, causing the payload to be delivered automatically whenever a new device establishes a remote session with the compromised host. By piggybacking on legitimate remote‑access traffic, the threat bypasses many traditional security controls that focus on inbound attacks, making detection more challenging for organizations that rely heavily on remote support tools.

ScreenConnect, rebranded as ConnectWise Control, is widely used by IT service providers and internal help desks to troubleshoot devices remotely. Its popularity and the trust placed in its encrypted communication channels have made it an attractive vector for threat actors seeking to move laterally within corporate networks. The VBScript payload, once executed, can perform a range of actions, including downloading additional malware, establishing persistence, and harvesting credentials, although the specific capabilities observed in the three incidents were limited to further propagation.

Huntress noted that the three cases appeared unrelated in terms of victim organizations and geographic locations, suggesting the campaign is being used by multiple actors rather than a single coordinated group. The researchers emphasized that the abuse of ScreenConnect is not a new phenomenon; however, the systematic chaining of the VBScript across newly connected hosts represents a novel escalation in the tool’s misuse. The report, first published by The Hacker News, urges administrators to audit their ScreenConnect deployments, verify client integrity, and apply any available security patches.

Experts recommend that organizations implement network segmentation to isolate remote‑access services, enforce strict authentication for remote sessions, and monitor for unusual outbound connections from devices running the ScreenConnect client. Additionally, endpoint detection and response (EDR) solutions should be tuned to flag the execution of unsigned VBScript files, especially when launched from the ScreenConnect process. As threat actors continue to weaponize legitimate software, vigilance in configuration management and continuous monitoring remains essential to prevent similar worm‑like spread mechanisms from compromising additional systems.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related