Hackers Hijack ScreenConnect to Spread Worm-Like VBScript Chain

·
Listen to this article~4 min
Hackers Hijack ScreenConnect to Spread Worm-Like VBScript Chain

Cybersecurity researchers have uncovered worm-like activity abusing ConnectWise ScreenConnect to spread a malicious VBScript payload. Learn how it works and how to protect your systems.

Cybersecurity researchers have uncovered a disturbing new trend: attackers are abusing ConnectWise ScreenConnect, a legitimate remote support tool, to spread a malicious VBScript payload to newly connected systems. This worm-like activity, detailed by Huntress, has been observed in three separate incidents, each using different initial access methods. ### How the Attack Unfolds The attacks start in various ways. In one case, a Quick Assist tech-support scam tricked users into granting remote access. In another, a phishing email delivered a malicious MSI installer. The third involved a fake software update. Once inside, the attackers leverage ScreenConnect to move laterally and drop a four-stage VBScript chain onto other machines that connect to the compromised host. This isn't just a one-off. It's a sophisticated, multi-stage infection that can quickly spread across a network. The VBScript chain is designed to evade detection and maintain persistence. It's a reminder that even trusted tools can be turned against you. ### Why This Matters for Your Business If you're using remote support software like ScreenConnect, you're a potential target. The attackers are counting on the fact that many organizations don't closely monitor their remote access tools. They slip in, set up shop, and then use your own infrastructure to infect others. The financial impact can be severe. A single breach can cost a small business anywhere from $10,000 to $50,000 in cleanup and lost productivity. For larger enterprises, that number can skyrocket into the millions. ### Protecting Yourself So, what can you do? First, educate your team about tech-support scams. No legitimate support technician will call you out of the blue and ask for remote access. Second, keep all software patched and up to date. Third, monitor your remote access logs for any unusual activity. > "The line between legitimate remote support and malicious access is blurring," says a Huntress researcher. "Organizations need to treat remote access tools with the same scrutiny as any other potential attack vector." - Implement multi-factor authentication (MFA) for all remote access tools. - Restrict who can use remote support software and when. - Regularly audit connected devices and sessions. - Use endpoint detection and response (EDR) solutions to catch unusual script activity. ### The Bigger Picture This campaign highlights a growing trend: attackers are increasingly abusing legitimate tools to fly under the radar. Antidetect browsers and other privacy tools are also part of this ecosystem, often used by attackers to hide their tracks. As a professional in this space, it's crucial to stay informed and proactive. Remember, cybersecurity is not a one-time fix. It's an ongoing process. Stay vigilant, keep learning, and don't underestimate the creativity of attackers. They only need one opening, and they're constantly looking for it. By understanding how these attacks work, you can better defend your organization. Share this information with your team, review your security protocols, and make sure your remote access tools are locked down tight.