Decoding the world of cybersecurity

Rogue ScreenConnect clients propagate malicious scripts

Huntress has observed modified ScreenConnect clients deploying malicious scripts and propagating the same activity to newly connected systems, while ConnectWise separately prepares a file-transfer fix.

Rogue ScreenConnect clients propagate malicious scripts
Summary
  • Huntress observed rogue ScreenConnect instances spawning VBScript and PowerShell across unrelated organisations.
  • Some malicious instances were configured to send the staged payload chain to newly connected ScreenConnect endpoints.
  • ConnectWise separately has a file-transfer flaw awaiting a patch; no causal link between that flaw and the campaign is established.

Rogue ScreenConnect installations are being used to deploy malicious scripts and propagate the same payload chain to additional connected systems, according to an investigation spanning several unrelated organisations.

Researchers at Huntress observed compromised endpoints running altered instances of ConnectWise ScreenConnect that repeatedly launched Windows Script Host processes and deployed a sequence of VBScript and PowerShell payloads.

The incidents began in late August and shared several characteristics despite affecting separate organisations. Huntress said the initial access involved social engineering and additional remote monitoring and management tools.

In one case, an attacker posing as technical support persuaded the victim to use Microsoft Quick Assist, giving the criminal interactive control of the machine. The attacker then executed a series of scripts and established further remote-access capability.

Other cases showed rogue ScreenConnect clients directly spawning the same malicious scripts from temporary directories. Huntress observed reconnaissance, persistence through a Windows Run key, PowerShell execution, privilege-related activity, and installation of additional remote-management software.

The more unusual behaviour involved propagation. Huntress said malicious ScreenConnect instances could detect new connections and deliver the staged script chain to additional endpoints connecting to the same rogue infrastructure.

That behaviour has prompted comparisons with a worm, although it is more precise to describe it as automated propagation through ScreenConnect connections. The observed campaign does not behave like a conventional network worm indiscriminately exploiting vulnerable devices across the internet.

Social engineering remains part of the initial access route documented by Huntress, while the malicious ScreenConnect deployment then provides a mechanism for extending the activity.

ConnectWise has separately disclosed a security issue affecting file-transfer behaviour in ScreenConnect Remote Access Support and Access sessions. The company says cloud and on-premises deployments are affected and that a formal fix and CVE are in development.

As an interim measure, ConnectWise has advised customers to disable technician file transfers.

The proximity of those developments makes the file-transfer issue relevant to the wider ScreenConnect security picture, but the available evidence does not establish that it enabled or caused the campaign observed by Huntress.

Keeping those two facts separate is important. A real malicious campaign is abusing ScreenConnect deployments, and a real ScreenConnect vulnerability is awaiting remediation, but they should not be described as one exploit chain unless technical evidence connects them.

Remote-management platforms create a sensitive dependency because their legitimate purpose is to perform actions that would look suspicious from an ordinary application. They can control endpoints, execute administrative tasks, transfer files, and maintain remote sessions across distributed estates.

That makes them useful to attackers when access can be established through social engineering, stolen credentials, a compromised management instance, or a product flaw.

The same operational requirement also limits simple defensive responses. Managed service providers and internal support teams often rely on remote-management software to maintain large numbers of systems, meaning the capability cannot always be disabled without affecting ordinary business operations.

Huntress’s investigation shows how legitimate support infrastructure can become part of the delivery mechanism once an attacker controls the relevant instance. Rather than introducing an unfamiliar remote-access tool alone, the malicious activity uses software whose presence may already be expected in the environment.

ConnectWise’s pending file-transfer fix introduces a separate reason to review ScreenConnect exposure. Until further technical evidence is published, however, the campaign and the vulnerability remain parallel security issues rather than a confirmed cause-and-effect relationship.

×