Cybersecurity researchers have unveiled a sophisticated exploit targeting ConnectWise’s ScreenConnect, using it to deploy malicious Visual Basic Scripts (VBScript) on new systems. This activity, observed in August 2026, involves a four-stage VBScript chain, leveraging worm-like propagation tactics to spread the threat.
Unraveling the Exploit Methodology
Huntress, a cybersecurity firm, identified three distinct incidents that employed various initial access methods. These included a tech-support scam via Quick Assist, a phishing attack delivering an MSI installer, and a deceptive Geek Squad refund form. Each method initiated a chain reaction leading to unauthorized ScreenConnect installations.
Once ScreenConnect was installed, the systems executed multiple VBScript files, namely 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The scripts enabled the execution of further malicious actions, facilitated by the spawned “wscript.exe” processes.
Detailed Attack Sequence
The attack follows a structured four-step process. Initially, 1.vbs evaluates the host’s environment, checking system resources and installed security solutions, and logs results to a temporary file. The second script, 2.vbs, monitors for this file to decide the next course of action, which involves downloading data from a now-defunct Dropbox link.
Subsequent scripts, 3.vbs and 4.vbs, use these evaluations to download encrypted payloads and execute PowerShell scripts to decrypt and implement further stages, potentially resulting in the deployment of a cryptocurrency miner or backdoor access.
Mitigation and Recommendations
The exploit’s complexity and its worm-like nature, which enables the infection to spread via new ScreenConnect connections, pose significant risks. Huntress advises affected systems to be re-imaged using reliable media or to perform a clean OS installation to neutralize the threat.
ConnectWise has responded by issuing a security advisory for ScreenConnect’s file transfer functionality. Users are advised to disable file transfer permissions within the administration settings to mitigate potential risks.
As cyber threats evolve, maintaining robust security protocols and staying informed about vulnerabilities is paramount for protecting organizational systems from exploitation.
