Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Multiple organizations experienced attacks beginning with social engineering that led to rogue ScreenConnect installations executing suspicious VBScript files. The attack chain involved four sequential VBScript payloads (1.vbs through 4.vbs) used to profile systems, check for security products, establish persistence, and deploy additional tools. Modified ScreenConnect clients enabled worm-like propagation by automatically transferring and executing these scripts on newly connected endpoints. The attacks included deployment of additional RMM tools like UltraViewer, cryptocurrency miners, and tunneling utilities. Systems were profiled based on installed security products, RAM capacity, and existing ScreenConnect installations. Persistence was achieved through Windows Registry Run Keys and concealed services. The campaign demonstrated sophisticated evasion techniques including AMSI bypass attempts, Windows Defender exclusions, and UAC bypass mechanisms.
Indicators of Compromise
- ip: 45.13.237.190
- hash: 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020
- hash: 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66
- hash: 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260
- hash: de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457
- hash: de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede
- hash: ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de
- url: http://homehub.opik.net:443
- domain: borertors92.anondns.net
- domain: homehub.opik.net
- domain: tele-sync.opik.net
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Description
Multiple organizations experienced attacks beginning with social engineering that led to rogue ScreenConnect installations executing suspicious VBScript files. The attack chain involved four sequential VBScript payloads (1.vbs through 4.vbs) used to profile systems, check for security products, establish persistence, and deploy additional tools. Modified ScreenConnect clients enabled worm-like propagation by automatically transferring and executing these scripts on newly connected endpoints. The attacks included deployment of additional RMM tools like UltraViewer, cryptocurrency miners, and tunneling utilities. Systems were profiled based on installed security products, RAM capacity, and existing ScreenConnect installations. Persistence was achieved through Windows Registry Run Keys and concealed services. The campaign demonstrated sophisticated evasion techniques including AMSI bypass attempts, Windows Defender exclusions, and UAC bypass mechanisms.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/rogue-screenconnect-installations"]
- Adversary
- null
- Pulse Id
- 6a992d01f9c5b93e1a1c58b6
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip45.13.237.190 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020 | — | |
hash110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66 | — | |
hash19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260 | — | |
hashde3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 | — | |
hashde89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede | — | |
hashffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://homehub.opik.net:443 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainborertors92.anondns.net | — | |
domainhomehub.opik.net | — | |
domaintele-sync.opik.net | — |
Threat ID: 6a996dadacd9273b49ef441a
Added to database: 09/03/2026, 12:53:01 UTC
Last updated: 09/03/2026, 15:38:39 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.