Overview
- Security researchers at Huntress found that attackers used modified ScreenConnect clients to execute a four-stage VBScript chain (1.vbs–4.vbs) that infects every new host the client connects to, creating worm-like propagation.
- ConnectWise confirmed the file-transfer behavior issue affects both cloud-hosted and on-premises ScreenConnect installations and advised administrators to remove the TransferFiles or TransferFilesInSession permission via Administration > Security > Roles immediately.
- Huntress observed the malware create a Windows Run key named WindowsServiceHost, repeatedly spawn wscript.exe, perform host discovery, install additional ScreenConnect clients, tunnel traffic, change security settings, and run a cryptocurrency miner in some cases.
- Internet-exposure magnifies the risk because Shadowserver tracks nearly 6,000 ScreenConnect instances online and CISA and past incidents show ScreenConnect has been repeatedly abused by ransomware gangs and state-backed actors.
- Administrators should check ScreenConnect audit logs for RunFiles or RanFiles entries tied to guest processes, reimage confirmed compromises from known-good media, apply the temporary permission change now, and install the forthcoming CVE-linked patch when it appears.