Cybersecurity experts at Huntress have alerted users to a cyberattack campaign leveraging modified ScreenConnect clients to distribute harmful software. These attacks, which mimic worm-like behavior, started in late August and involve tricking users into installing rogue clients on their devices.
Methods of Propagation
The campaign typically begins when attackers deploy these altered ScreenConnect clients through social engineering tactics. Once installed, these clients continually spawn Windows Script Host (wscript.exe) processes, deploying four distinct VBScript files. This pattern has been consistently observed across multiple organizations.
Notably, the attackers have been using these rogue clients to extend their reach to other connected systems. They achieve persistence by creating a User Run Key, which points to an additional VBScript file. This allows the malicious payload to remain active even after a system reboot.
Social Engineering Tactics
On August 20, attackers posing as technical support staff deceived a user into launching Quick Assist, a built-in Windows remote support tool. This allowed them to gain control over the machine and execute five VBScript files before the attack was intercepted. Similar attacks were noted on the same day, suggesting a widespread phishing effort.
Huntress reported that the rogue clients quickly launched the VBScript files from a temporary directory. Network monitoring revealed ongoing connections from ScreenConnect to various remote IP addresses, indicating a coordinated effort to disperse the payload.
Recommendations and Precautions
Huntress urges administrators to scrutinize any on-premises ScreenConnect installations closely. The rogue clients not only deploy scripts for system reconnaissance and payload staging but also execute PowerShell scripts that attempt to erase evidence and bypass User Account Control (UAC).
In response to the threat, ConnectWise issued an advisory regarding a file transfer vulnerability in ScreenConnect, affecting both cloud and on-premises setups. An official fix is expected soon, but until then, disabling file transfer functionality is advised to mitigate risks.
The ongoing use of social engineering and sophisticated scripting underscores the need for heightened vigilance and proactive measures in cybersecurity management.
