{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/screenconnect-remote-access/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ScreenConnect Remote Access"],"_cs_severities":["high"],"_cs_tags":["worm","social-engineering","remote-access","malware"],"_cs_type":"advisory","_cs_vendors":["ConnectWise"],"content_html":"\u003cp\u003eIn August 2026, researchers observed a worm-like campaign abusing ConnectWise ScreenConnect to deploy malicious VBScript chains. Attackers achieve initial access through various social engineering tactics, including tech-support scams using Quick Assist, phishing-delivered MSI installers, and fake refund forms. Once a rogue ScreenConnect client is installed, it repeatedly spawns 'wscript.exe' to execute a sequence of four VBScript files (1.vbs through 4.vbs). This chain profiles the host, enumerates security software (e.g., CrowdStrike, SentinelOne, Sophos), and downloads modular payloads based on system state variables. The malware exhibits worm-like propagation by infecting host machines that connect to an already compromised ScreenConnect client. Depending on the environment, the payload can result in user-level backdoors, UAC bypass for privilege escalation, or the deployment of XMRig cryptocurrency miners. ConnectWise has acknowledged an issue with file transfer behavior in ScreenConnect remote access sessions that facilitates this activity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established via social engineering (Quick Assist scam, phishing MSI, or fake refund lures) to deploy a rogue ScreenConnect remote access client.\u003c/li\u003e\n\u003cli\u003eThe rogue ScreenConnect client triggers the execution of '1.vbs' using 'wscript.exe', which profiles host resources, enumerates installed security products, and writes a state variable to '%TEMP%\\value.txt'.\u003c/li\u003e\n\u003cli\u003e'2.vbs' is executed, which checks the state variable and downloads an initial configuration file ('map.txt') from a remote source.\u003c/li\u003e\n\u003cli\u003e'3.vbs' downloads a secondary payload ('out.enc') based on the state variable defined in the first stage.\u003c/li\u003e\n\u003cli\u003e'4.vbs' launches 'runner.ps1' to decrypt 'out.enc', writing the result to '%APPDATA%\\Microsoft\\Windows\\Templates\\Classic\\sys_cache.zip'.\u003c/li\u003e\n\u003cli\u003eThe chain executes a final PowerShell script, 'PyTorchFix.ps1', to finalize the installation of backdoors, privilege escalation tools, or cryptominers.\u003c/li\u003e\n\u003cli\u003eThe malware achieves persistence by creating a 'WindowsServiceHost' User Run key pointing to 'WindowsServiceHost.vbs'.\u003c/li\u003e\n\u003cli\u003eThe infection propagates as the compromised client records 'ConnectionID' identifiers, infecting subsequent hosts that initiate new ScreenConnect sessions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eImpacted organizations face the risk of persistent remote access backdoors, privilege escalation, and unauthorized cryptocurrency mining. Multiple incidents have been identified involving diverse social engineering lures. If successful, the attack results in total system compromise, potential data exfiltration, and lateral movement across remote support infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDisable the 'TransferFiles' and 'TransferFilesInSession' permissions within all ConnectWise ScreenConnect role definitions to mitigate the file transfer vector.\u003c/li\u003e\n\u003cli\u003eImplement endpoint detection rules to monitor for 'wscript.exe' or 'cscript.exe' spawning from 'ScreenConnect.Client.exe' or related processes in the temporary directory.\u003c/li\u003e\n\u003cli\u003eHunt for 'WindowsServiceHost' Run key modifications and associated 'WindowsServiceHost.vbs' files in user AppData directories.\u003c/li\u003e\n\u003cli\u003eBlock communication to the identified C2 infrastructure (e.g., 45.13.237.190, 131.123.40.98, tele-sync.opik.net) at the network perimeter.\u003c/li\u003e\n\u003cli\u003eGiven the worm-like persistence and potential for deep-system compromise, re-image infected hosts from known-good media.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T12:56:11Z","date_published":"2026-09-07T12:56:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rogue-screenconnect-worm/","summary":"Threat actors are using compromised ConnectWise ScreenConnect instances to propagate a worm-like, four-stage VBScript infection chain that enables backdooring, UAC bypass, and cryptojacking on connected hosts.","title":"Rogue ScreenConnect Clients Distribute Four-Stage VBScript Malware","url":"https://feed.craftedsignal.io/briefs/2026-09-rogue-screenconnect-worm/"}],"language":"en","title":"CraftedSignal Threat Feed - ScreenConnect Remote Access","version":"https://jsonfeed.org/version/1.1"}