Act
active
Rogue ScreenConnect Clients Spread Four-Stage VBScript Worm to New Hosts
- Engineer — Act: Three confirmed incidents show worm-like spread via ScreenConnect to newly connected hosts — if you run ScreenConnect, audit your relay configuration for unauthorized clients and review logs for unexpected new-host onboarding activity since the worm spreads automatically on connection.
- SOC/IR — Act: Hunt for VBScript execution chains spawned from ScreenConnect parent processes across your estate, and sweep RMM logs for abnormal new-client connection events; initial access spans tech-support scam lures, phishing MSIs, and at least one other vector, so assume diverse entry points.
- Leader — Plan: RMM tool abuse as a worm vector is a growing pattern — use this quarter to review governance of ScreenConnect and similar remote-access tools (access restrictions, audit logging, approved-relay allowlists) before an incident forces the conversation.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.