ScreenConnect Weaponized as a Self-Propagating Worm
Cybercriminals have transformed ScreenConnect into a weaponized mechanism capable of infecting other ScreenConnect systems during standard connections. The modified client automatically detects a new session, dispatches malicious scripts via the native file transfer feature, and initiates an infection chain on the connecting endpoint, operating much like a computer worm.
Initial Infection Vectors
The Huntress team uncovered this insidious scheme in late August across several unrelated organizations. Initially, each compromise required human interaction. In one instance, fraudsters persuaded a victim to launch Windows Quick Assist. Another scenario involved distributing a malicious ScreenConnect payload via phishing emails. A third victim, seeking a Geek Squad refund form, inadvertently downloaded a counterfeit remote access client.
Upon successful installation, the rogue ScreenConnect iteration executed four distinct scripts via the wscript engine, bearing the rudimentary monikers 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The initial script meticulously surveyed the system, verifying the presence of ScreenConnect, evaluating the random access memory capacity, and scanning for security solutions from vendors such as Huntress, CrowdStrike, SentinelOne, Sophos, and Malwarebytes.
Deploying the Malicious Payload
Should the machine prove suitable for subsequent exploitation, the following stages downloaded encrypted components and tailored the payload arsenal specifically for that host. Depending on the variant, the attackers deployed a clandestine ScreenConnect backdoor, privilege escalation utilities, a wstunnel implementation, and the XMRig cryptocurrency miner. Furthermore, the scripts attempted to bypass User Account Control through the ms-settings handler, interfere with the Antimalware Scan Interface, append the user directory to Microsoft Defender exclusions, and disable various native Windows security mechanisms.
The Hidden Worm Propagation Mechanism
However, the most extraordinary element remained concealed within the modified ScreenConnect client itself. Huntress identified altered builds spanning nine different versions of the software, designed to continuously monitor for fresh ScreenConnect connections, as detailed in their comprehensive report on rogue ScreenConnect installations. The moment a new host session materialized, the compromised client registered four VBS files within the integrated file transfer system, configured them with a run action, and propelled them to the opposite end of the connection.
Thus, a standard Remote Monitoring and Management platform acquired worm-like propagation capabilities, entirely circumventing traditional network scanning or vulnerability hunting. The subsequent victim became the very device that legitimately connected to the infected client during routine administrative operations. The malicious client memorized the active session identifier to prevent redundant attacks; however, it purged this token upon disconnection. Consequently, a subsequent reconnection could trigger the infection process anew.
ConnectWise Response and Security Advisories
On September 3rd, ConnectWise acknowledged the file transfer vulnerability within ScreenConnect Remote Access Support and Access, detailing the issue in their official security trust advisories. This flaw impacts both cloud-based and on-premises deployments. While developers prepare a comprehensive patch, the company advises administrators to disable file transfer privileges for technicians via the TransferFiles or TransferFilesInSession permissions. The manufacturer has also pledged to assign a CVE identifier to this issue and release an official remediation. Nevertheless, ConnectWise has not yet publicly confirmed a direct technical correlation between the discovered file transfer defect and the active campaign identified by Huntress.
Remediation and Defense Strategies
In their technical breakdown, Huntress experts recommend treating RunFiles and RanFiles entries as highly suspicious when scripts execute under the guest process context. Furthermore, they strongly advise rebuilding compromised machines from a verifiably clean installation medium. The researchers caution against relying solely on the initial script nomenclature, as threat actors can easily alter these filenames.
This resulting paradigm presents an exceptionally grave danger to IT support desks and Managed Service Providers. A utility explicitly designed for connecting to a vast multitude of client endpoints and transferring files transforms into a potent malware distribution conduit following a compromise. To facilitate the next infection, the attackers no longer need to deceive a human into executing a malicious payload. They simply await the next legitimate ScreenConnect session.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.