Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
Security researchers at Huntress have uncovered a new attack method that abuses ConnectWise ScreenConnect, a legitimate remote support tool, to spread malicious scripts automatically. Three separate incidents in August 2026 began through different tricks, including a fake tech-support scam, a phishing email with a malicious installer, and a fraudulent refund form, but all led to the same outcome: a compromised ScreenConnect client running a four-stage VBScript chain named 1.vbs through 4.vbs.
Once installed, the infected client behaves like a worm. Every time a new host connects to the compromised ScreenConnect session, it can trigger the same four-stage script chain on that new system, effectively turning the infected machine into a distribution point for malware. The scripts also clean up after themselves, terminating related processes and deleting staging files once the infection completes, and they track connection IDs to avoid repeatedly targeting the same session while still allowing reinfection on reconnection.
Huntress also observed other remote monitoring tools, such as UltraViewer, present on some affected systems, along with a suspicious registry entry pointing to a file called WindowsServiceHost.vbs. This suggests attackers may be using multiple remote access tools as part of a broader intrusion toolkit.