Modified ScreenConnect Clients Used in Worm-Like Campaign
A worm-like campaign uses modified ScreenConnect clients with backdoors to spread malicious payloads to connected endpoints. The attacks start with social engineering to deploy rogue ScreenConnect instances that execute VBScript files for reconnaissance, persistence, and payload staging. The attacker establishes persistence via User Run Keys and installs additional remote desktop software. ConnectWise has acknowledged a file transfer issue affecting ScreenConnect and plans to issue a CVE and fix soon, recommending disabling file transfer in the meantime.
AI Analysis
Technical Summary
This campaign involves attackers deploying backdoored ScreenConnect clients on victim machines through social engineering. These rogue clients spawn multiple VBScript files that perform system reconnaissance, stage payloads, and execute PowerShell scripts to erase evidence, attempt UAC bypass, and install concealed ScreenConnect clients. The malicious clients propagate the payload to other connected ScreenConnect endpoints, effectively acting in a worm-like manner. Persistence is established via User Run Keys and installation of UltraViewer remote desktop software. ConnectWise has confirmed a file transfer vulnerability affecting both cloud and on-premises ScreenConnect deployments and plans to release a CVE and official fix shortly. Until then, disabling file transfer functionality is advised to reduce risk.
Potential Impact
The campaign enables attackers to spread malicious payloads laterally across networks using compromised ScreenConnect clients, potentially leading to unauthorized remote control of multiple endpoints. Persistence mechanisms and payload propagation increase the risk of widespread infection within affected environments. The vulnerability affects both cloud and on-premises ScreenConnect deployments, increasing the attack surface.
Mitigation Recommendations
ConnectWise has announced an upcoming official fix and CVE for the file transfer vulnerability in ScreenConnect. Until the patch is released, administrators should disable the file transfer functionality in ScreenConnect to mitigate risk. Additional scrutiny of on-premises ScreenConnect installations is recommended. Follow ConnectWise advisories for updates and apply the official fix promptly once available.
Modified ScreenConnect Clients Used in Worm-Like Campaign
Description
A worm-like campaign uses modified ScreenConnect clients with backdoors to spread malicious payloads to connected endpoints. The attacks start with social engineering to deploy rogue ScreenConnect instances that execute VBScript files for reconnaissance, persistence, and payload staging. The attacker establishes persistence via User Run Keys and installs additional remote desktop software. ConnectWise has acknowledged a file transfer issue affecting ScreenConnect and plans to issue a CVE and fix soon, recommending disabling file transfer in the meantime.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves attackers deploying backdoored ScreenConnect clients on victim machines through social engineering. These rogue clients spawn multiple VBScript files that perform system reconnaissance, stage payloads, and execute PowerShell scripts to erase evidence, attempt UAC bypass, and install concealed ScreenConnect clients. The malicious clients propagate the payload to other connected ScreenConnect endpoints, effectively acting in a worm-like manner. Persistence is established via User Run Keys and installation of UltraViewer remote desktop software. ConnectWise has confirmed a file transfer vulnerability affecting both cloud and on-premises ScreenConnect deployments and plans to release a CVE and official fix shortly. Until then, disabling file transfer functionality is advised to reduce risk.
Potential Impact
The campaign enables attackers to spread malicious payloads laterally across networks using compromised ScreenConnect clients, potentially leading to unauthorized remote control of multiple endpoints. Persistence mechanisms and payload propagation increase the risk of widespread infection within affected environments. The vulnerability affects both cloud and on-premises ScreenConnect deployments, increasing the attack surface.
Defensive Guidance
ConnectWise has announced an upcoming official fix and CVE for the file transfer vulnerability in ScreenConnect. Until the patch is released, administrators should disable the file transfer functionality in ScreenConnect to mitigate risk. Additional scrutiny of on-premises ScreenConnect installations is recommended. Follow ConnectWise advisories for updates and apply the official fix promptly once available.
Technical Details
- Classification
- {"confidence":0.76,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/","fetched":true,"fetchedAt":"2026-09-07T11:52:59.770Z","wordCount":1112}
Threat ID: 6a9ea59bacd9273b498cdd36
Added to database: 09/07/2026, 11:52:59 UTC
Last enriched: 09/07/2026, 11:53:04 UTC
Last updated: 09/07/2026, 19:28:07 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.