Particle.news

ScreenConnect File-Transfer Flaw Lets Rogue Clients Spread VBScript Worm

Modified ScreenConnect clients can push a four-stage VBScript chain that propagates to newly connected machines, prompting ConnectWise to tell administrators to disable file-transfer permissions until a CVE and patch are released this week.

Overview

  • Security researchers at Huntress found that attackers used modified ScreenConnect clients to execute a four-stage VBScript chain (1.vbs–4.vbs) that infects every new host the client connects to, creating worm-like propagation.
  • ConnectWise confirmed the file-transfer behavior issue affects both cloud-hosted and on-premises ScreenConnect installations and advised administrators to remove the TransferFiles or TransferFilesInSession permission via Administration > Security > Roles immediately.
  • Huntress observed the malware create a Windows Run key named WindowsServiceHost, repeatedly spawn wscript.exe, perform host discovery, install additional ScreenConnect clients, tunnel traffic, change security settings, and run a cryptocurrency miner in some cases.
  • Internet-exposure magnifies the risk because Shadowserver tracks nearly 6,000 ScreenConnect instances online and CISA and past incidents show ScreenConnect has been repeatedly abused by ransomware gangs and state-backed actors.
  • Administrators should check ScreenConnect audit logs for RunFiles or RanFiles entries tied to guest processes, reimage confirmed compromises from known-good media, apply the temporary permission change now, and install the forthcoming CVE-linked patch when it appears.