HackerFeeds

CyberSecurity News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

The Hacker News
· September 7, 2026

AI summary

Cybersecurity researchers have found that malicious actors are using ConnectWise ScreenConnect to spread a malicious VBScript payload to newly connected systems. This worm-like activity has been observed in three unrelated incidents, which used different initial access methods. The methods included a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake entity. The payload is distributed in a four-stage chain. The incidents were identified by Huntress, which disclosed details of the malicious activity. The diverse initial access methods suggest that the attackers are using various tactics to gain initial access to systems.

Read the full article at The Hacker Newsthehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.