CyberSecurity News
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
AI summary
Cybersecurity researchers have found that malicious actors are using ConnectWise ScreenConnect to spread a malicious VBScript payload to newly connected systems. This worm-like activity has been observed in three unrelated incidents, which used different initial access methods. The methods included a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake entity. The payload is distributed in a four-stage chain. The incidents were identified by Huntress, which disclosed details of the malicious activity. The diverse initial access methods suggest that the attackers are using various tactics to gain initial access to systems.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

