Rogue ScreenConnect Clients Spread FourStage VBScript Chain to Newly Connected Hosts
News Source : Internet
News Summary
- Researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
- Three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure.
- Across these incidents, the attack sequence is said to have followed a four-step process, with each VBScript launching the next and allowing it to progress further.
Never miss a story from us, subscribe to our newsletter