CuraSec

Act active

Rogue ScreenConnect Clients Spread Four-Stage VBScript Worm to New Hosts

2026-09-07 16:27 UTC · The Hacker News · read the source ↗ #screenconnect#rmm-abuse#vbscript-malware
  • Engineer — Act: Three confirmed incidents show worm-like spread via ScreenConnect to newly connected hosts — if you run ScreenConnect, audit your relay configuration for unauthorized clients and review logs for unexpected new-host onboarding activity since the worm spreads automatically on connection.
  • SOC/IR — Act: Hunt for VBScript execution chains spawned from ScreenConnect parent processes across your estate, and sweep RMM logs for abnormal new-client connection events; initial access spans tech-support scam lures, phishing MSIs, and at least one other vector, so assume diverse entry points.
  • Leader — Plan: RMM tool abuse as a worm vector is a growing pattern — use this quarter to review governance of ScreenConnect and similar remote-access tools (access restrictions, audit logging, approved-relay allowlists) before an incident forces the conversation.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.