Threat Intelligence

Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain

The Hacker News · 7 Sept 2026
Key Takeaway Businesses using ScreenConnect or similar remote access tools should monitor for unexpected script executions and unfamiliar remote monitoring software, and train staff to recognise tech-support scams and phishing lures as common entry points.

Security researchers at Huntress have uncovered a new attack method that abuses ConnectWise ScreenConnect, a legitimate remote support tool, to spread malicious scripts automatically. Three separate incidents in August 2026 began through different tricks, including a fake tech-support scam, a phishing email with a malicious installer, and a fraudulent refund form, but all led to the same outcome: a compromised ScreenConnect client running a four-stage VBScript chain named 1.vbs through 4.vbs.

Once installed, the infected client behaves like a worm. Every time a new host connects to the compromised ScreenConnect session, it can trigger the same four-stage script chain on that new system, effectively turning the infected machine into a distribution point for malware. The scripts also clean up after themselves, terminating related processes and deleting staging files once the infection completes, and they track connection IDs to avoid repeatedly targeting the same session while still allowing reinfection on reconnection.

Huntress also observed other remote monitoring tools, such as UltraViewer, present on some affected systems, along with a suspicious registry entry pointing to a file called WindowsServiceHost.vbs. This suggests attackers may be using multiple remote access tools as part of a broader intrusion toolkit.

ScreenConnect malware remote access tools phishing VBScript

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.