Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

0
Medium
Published: 09/03/2026 (09/03/2026, 08:17:05 UTC)
Source: AlienVault OTX General

Description

Multiple organizations experienced attacks beginning with social engineering that led to rogue ScreenConnect installations executing suspicious VBScript files. The attack chain involved four sequential VBScript payloads (1.vbs through 4.vbs) used to profile systems, check for security products, establish persistence, and deploy additional tools. Modified ScreenConnect clients enabled worm-like propagation by automatically transferring and executing these scripts on newly connected endpoints. The attacks included deployment of additional RMM tools like UltraViewer, cryptocurrency miners, and tunneling utilities. Systems were profiled based on installed security products, RAM capacity, and existing ScreenConnect installations. Persistence was achieved through Windows Registry Run Keys and concealed services. The campaign demonstrated sophisticated evasion techniques including AMSI bypass attempts, Windows Defender exclusions, and UAC bypass mechanisms.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/rogue-screenconnect-installations"]
Adversary
null
Pulse Id
6a992d01f9c5b93e1a1c58b6
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip45.13.237.190

Hash

ValueDescriptionCopy
hash08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020
hash110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66
hash19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260
hashde3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457
hashde89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede
hashffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de

Url

ValueDescriptionCopy
urlhttp://homehub.opik.net:443

Domain

ValueDescriptionCopy
domainborertors92.anondns.net
domainhomehub.opik.net
domaintele-sync.opik.net

Threat ID: 6a996dadacd9273b49ef441a

Added to database: 09/03/2026, 12:53:01 UTC

Last updated: 09/03/2026, 15:38:39 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses