Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ScreenConnect Exploited to Spread Malicious Scripts

ScreenConnect Exploited to Spread Malicious Scripts

Posted on September 7, 2026 By CWS

Cybersecurity researchers have unveiled a sophisticated exploit targeting ConnectWise’s ScreenConnect, using it to deploy malicious Visual Basic Scripts (VBScript) on new systems. This activity, observed in August 2026, involves a four-stage VBScript chain, leveraging worm-like propagation tactics to spread the threat.

Unraveling the Exploit Methodology

Huntress, a cybersecurity firm, identified three distinct incidents that employed various initial access methods. These included a tech-support scam via Quick Assist, a phishing attack delivering an MSI installer, and a deceptive Geek Squad refund form. Each method initiated a chain reaction leading to unauthorized ScreenConnect installations.

Once ScreenConnect was installed, the systems executed multiple VBScript files, namely 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The scripts enabled the execution of further malicious actions, facilitated by the spawned “wscript.exe” processes.

Detailed Attack Sequence

The attack follows a structured four-step process. Initially, 1.vbs evaluates the host’s environment, checking system resources and installed security solutions, and logs results to a temporary file. The second script, 2.vbs, monitors for this file to decide the next course of action, which involves downloading data from a now-defunct Dropbox link.

Subsequent scripts, 3.vbs and 4.vbs, use these evaluations to download encrypted payloads and execute PowerShell scripts to decrypt and implement further stages, potentially resulting in the deployment of a cryptocurrency miner or backdoor access.

Mitigation and Recommendations

The exploit’s complexity and its worm-like nature, which enables the infection to spread via new ScreenConnect connections, pose significant risks. Huntress advises affected systems to be re-imaged using reliable media or to perform a clean OS installation to neutralize the threat.

ConnectWise has responded by issuing a security advisory for ScreenConnect’s file transfer functionality. Users are advised to disable file transfer permissions within the administration settings to mitigate potential risks.

As cyber threats evolve, maintaining robust security protocols and staying informed about vulnerabilities is paramount for protecting organizational systems from exploitation.

The Hacker News Tags:ConnectWise, Cybersecurity, Malware, Phishing, remote access, RMM tools, ScreenConnect, security vulnerability, VBScript, worm-like activity

Post navigation

Previous Post: Roundcube Webmail Addresses 12 Security Vulnerabilities
Next Post: OpenAI Agents Overrun German Wiki Site, Spark Concerns

Related Posts

AI Hallucinations Pose New Security Challenges AI Hallucinations Pose New Security Challenges The Hacker News
New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands The Hacker News
Exploring NDR Systems: A Hands-On Experience Exploring NDR Systems: A Hands-On Experience The Hacker News
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations The Hacker News
INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty The Hacker News
Typosquatting Campaign Targets RubyGems Users’ Data Typosquatting Campaign Targets RubyGems Users’ Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms
  • Telerik UI Vulnerability: Security Flaw Exposes Systems
  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms
  • Telerik UI Vulnerability: Security Flaw Exposes Systems
  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark