
highmalware
Rogue ScreenConnect Clients Deploy Four-Stage VBScript Chain to Newly Connected Hosts
Researchers from Huntress have detailed activity abusing ConnectWise ScreenConnect to distribute a malicious four-stage VBScript payload to newly connected systems. The incidents, observed in September 2026, leveraged diverse initial access methods including a tech-support scam, a phishing-delivered MSI installer, and a fake update mechanism. The abuse allows unauthorized execution of VBScript chains on newly connected hosts, posing risks of further compromise and lateral movement.
The Hacker News1 min read