Rogue ScreenConnect Clients Spread FourStage VBScript Chain to Newly Connected Hosts

Image for article Rogue ScreenConnect Clients Spread FourStage VBScript Chain to Newly Connected Hosts
News Source : Internet

News Summary

  • Researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
  • Three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure.
  • Across these incidents, the attack sequence is said to have followed a four-step process, with each VBScript launching the next and allowing it to progress further.

Must read Articles