Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ScreenConnect Exploited in Cyberattack Campaign

ScreenConnect Exploited in Cyberattack Campaign

Posted on September 7, 2026 By CWS

Cybersecurity experts at Huntress have alerted users to a cyberattack campaign leveraging modified ScreenConnect clients to distribute harmful software. These attacks, which mimic worm-like behavior, started in late August and involve tricking users into installing rogue clients on their devices.

Methods of Propagation

The campaign typically begins when attackers deploy these altered ScreenConnect clients through social engineering tactics. Once installed, these clients continually spawn Windows Script Host (wscript.exe) processes, deploying four distinct VBScript files. This pattern has been consistently observed across multiple organizations.

Notably, the attackers have been using these rogue clients to extend their reach to other connected systems. They achieve persistence by creating a User Run Key, which points to an additional VBScript file. This allows the malicious payload to remain active even after a system reboot.

Social Engineering Tactics

On August 20, attackers posing as technical support staff deceived a user into launching Quick Assist, a built-in Windows remote support tool. This allowed them to gain control over the machine and execute five VBScript files before the attack was intercepted. Similar attacks were noted on the same day, suggesting a widespread phishing effort.

Huntress reported that the rogue clients quickly launched the VBScript files from a temporary directory. Network monitoring revealed ongoing connections from ScreenConnect to various remote IP addresses, indicating a coordinated effort to disperse the payload.

Recommendations and Precautions

Huntress urges administrators to scrutinize any on-premises ScreenConnect installations closely. The rogue clients not only deploy scripts for system reconnaissance and payload staging but also execute PowerShell scripts that attempt to erase evidence and bypass User Account Control (UAC).

In response to the threat, ConnectWise issued an advisory regarding a file transfer vulnerability in ScreenConnect, affecting both cloud and on-premises setups. An official fix is expected soon, but until then, disabling file transfer functionality is advised to mitigate risks.

The ongoing use of social engineering and sophisticated scripting underscores the need for heightened vigilance and proactive measures in cybersecurity management.

Security Week News Tags:ConnectWise, Cyberattack, Cybersecurity, file transfer, malicious payload, Malware, network security, Phishing, PowerShell, remote access, ScreenConnect, social engineering, UAC bypass, UltraViewer, VBScript

Post navigation

Previous Post: Executives Targeted in Microsoft 365 Data Extortion Scam
Next Post: Switzerland to Test Open-Source Alternative to Microsoft 365

Related Posts

Cyberattack On Russian Airline Aeroflot Causes the Cancellation of More Than 100 Flights Cyberattack On Russian Airline Aeroflot Causes the Cancellation of More Than 100 Flights Security Week News
Train Hack Gets Proper Attention After 20 Years: Researcher  Train Hack Gets Proper Attention After 20 Years: Researcher  Security Week News
Hack Targets French Government Messaging Platform Hack Targets French Government Messaging Platform Security Week News
Ransomware Attack Targets Advantest’s Network Ransomware Attack Targets Advantest’s Network Security Week News
Jamf to Go Private Following .2 Billion Acquisition by Francisco Partners Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners Security Week News
Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions Turla and Gamaredon Working Together in Fresh Ukrainian Intrusions Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark