Altered ScreenConnect clients used to spread malware

 

Altered ScreenConnect clients used to spread malware

Modified ScreenConnect clients are being used in attacks to spread malware to other computers, according to a new report from cybersecurity firm Huntress.

The attacks began in late August and appear to start with social engineering. In one incident, a hacker posing as tech support convinced a victim to use Windows Quick Assist, giving the attacker remote access to the computer.

The attacker then installed a rogue ScreenConnect client, which launched several VBScript files. Huntress found the same scripts being used in attacks against other organizations.

The scripts were designed to collect information about infected systems, prepare and run additional malware, and maintain access to compromised machines. The attackers also used a Windows User Run Key to keep the malware running after a restart and installed UltraViewer for remote access.

Huntress says the rogue ScreenConnect clients can also look for other ScreenConnect systems and spread the malicious scripts to them in worm-like attacks.

That being said, administrators are strongly recommended to check on-premises ScreenConnect installations.

Last week, ConnectWise warned about an unspecified issue affecting file transfers in ScreenConnect. The company recommends to temporarily disable the file transfer feature while it prepares a fix.


Back to the list