Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ScreenConnect Exploited to Spread Malicious Scripts

ScreenConnect Exploited to Spread Malicious Scripts

Posted on September 7, 2026 By CWS

Cybersecurity researchers have unveiled a sophisticated exploit targeting ConnectWise’s ScreenConnect, using it to deploy malicious Visual Basic Scripts (VBScript) on new systems. This activity, observed in August 2026, involves a four-stage VBScript chain, leveraging worm-like propagation tactics to spread the threat.

Unraveling the Exploit Methodology

Huntress, a cybersecurity firm, identified three distinct incidents that employed various initial access methods. These included a tech-support scam via Quick Assist, a phishing attack delivering an MSI installer, and a deceptive Geek Squad refund form. Each method initiated a chain reaction leading to unauthorized ScreenConnect installations.

Once ScreenConnect was installed, the systems executed multiple VBScript files, namely 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The scripts enabled the execution of further malicious actions, facilitated by the spawned “wscript.exe” processes.

Detailed Attack Sequence

The attack follows a structured four-step process. Initially, 1.vbs evaluates the host’s environment, checking system resources and installed security solutions, and logs results to a temporary file. The second script, 2.vbs, monitors for this file to decide the next course of action, which involves downloading data from a now-defunct Dropbox link.

Subsequent scripts, 3.vbs and 4.vbs, use these evaluations to download encrypted payloads and execute PowerShell scripts to decrypt and implement further stages, potentially resulting in the deployment of a cryptocurrency miner or backdoor access.

Mitigation and Recommendations

The exploit’s complexity and its worm-like nature, which enables the infection to spread via new ScreenConnect connections, pose significant risks. Huntress advises affected systems to be re-imaged using reliable media or to perform a clean OS installation to neutralize the threat.

ConnectWise has responded by issuing a security advisory for ScreenConnect’s file transfer functionality. Users are advised to disable file transfer permissions within the administration settings to mitigate potential risks.

As cyber threats evolve, maintaining robust security protocols and staying informed about vulnerabilities is paramount for protecting organizational systems from exploitation.

The Hacker News Tags:ConnectWise, Cybersecurity, Malware, Phishing, remote access, RMM tools, ScreenConnect, security vulnerability, VBScript, worm-like activity

Post navigation

Previous Post: Roundcube Webmail Addresses 12 Security Vulnerabilities
Next Post: OpenAI Agents Overrun German Wiki Site, Spark Concerns

Related Posts

What 2025 Is Teaching Us About Cloud Defense What 2025 Is Teaching Us About Cloud Defense The Hacker News
North Korean macOS Scam Uses Fake Updates to Steal Crypto North Korean macOS Scam Uses Fake Updates to Steal Crypto The Hacker News
SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics The Hacker News
LLM Agent Exploitation Follows Marimo Vulnerability Attack LLM Agent Exploitation Follows Marimo Vulnerability Attack The Hacker News
Google and Rivals Launch Advanced Cybersecurity AI Models Google and Rivals Launch Advanced Cybersecurity AI Models The Hacker News
Rokarolla Malware Targets Banking Apps with Advanced Tactics Rokarolla Malware Targets Banking Apps with Advanced Tactics The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns
  • ScreenConnect Exploited to Spread Malicious Scripts
  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Minecraft Mod Distributes Myth Stealer RAT
  • OpenAI Agents Overrun German Wiki Site, Spark Concerns
  • ScreenConnect Exploited to Spread Malicious Scripts
  • Roundcube Webmail Addresses 12 Security Vulnerabilities
  • North Korea Utilizes New Linux Toolkit in Espionage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark