Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Modified ScreenConnect Clients Used in Worm-Like Campaign

0
High
Malware
Published: 09/07/2026 (09/07/2026, 11:45:48 UTC)
Source: SecurityWeek

Description

A worm-like campaign uses modified ScreenConnect clients with backdoors to spread malicious payloads to connected endpoints. The attacks start with social engineering to deploy rogue ScreenConnect instances that execute VBScript files for reconnaissance, persistence, and payload staging. The attacker establishes persistence via User Run Keys and installs additional remote desktop software. ConnectWise has acknowledged a file transfer issue affecting ScreenConnect and plans to issue a CVE and fix soon, recommending disabling file transfer in the meantime.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 11:53:04 UTC

Technical Analysis

This campaign involves attackers deploying backdoored ScreenConnect clients on victim machines through social engineering. These rogue clients spawn multiple VBScript files that perform system reconnaissance, stage payloads, and execute PowerShell scripts to erase evidence, attempt UAC bypass, and install concealed ScreenConnect clients. The malicious clients propagate the payload to other connected ScreenConnect endpoints, effectively acting in a worm-like manner. Persistence is established via User Run Keys and installation of UltraViewer remote desktop software. ConnectWise has confirmed a file transfer vulnerability affecting both cloud and on-premises ScreenConnect deployments and plans to release a CVE and official fix shortly. Until then, disabling file transfer functionality is advised to reduce risk.

Potential Impact

The campaign enables attackers to spread malicious payloads laterally across networks using compromised ScreenConnect clients, potentially leading to unauthorized remote control of multiple endpoints. Persistence mechanisms and payload propagation increase the risk of widespread infection within affected environments. The vulnerability affects both cloud and on-premises ScreenConnect deployments, increasing the attack surface.

Defensive Guidance

ConnectWise has announced an upcoming official fix and CVE for the file transfer vulnerability in ScreenConnect. Until the patch is released, administrators should disable the file transfer functionality in ScreenConnect to mitigate risk. Additional scrutiny of on-premises ScreenConnect installations is recommended. Follow ConnectWise advisories for updates and apply the official fix promptly once available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.76,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/","fetched":true,"fetchedAt":"2026-09-07T11:52:59.770Z","wordCount":1112}

Threat ID: 6a9ea59bacd9273b498cdd36

Added to database: 09/07/2026, 11:52:59 UTC

Last enriched: 09/07/2026, 11:53:04 UTC

Last updated: 09/07/2026, 19:28:07 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses