Huntress identified a campaign in which attackers use social engineering—including fake technical support, phishing, fraudulent refund-search results, and Quick Assist abuse—to persuade victims to install trojanized ConnectWise ScreenConnect clients. Rather than exploiting a ScreenConnect vulnerability, the altered remote-support software detects incoming sessions and uses ScreenConnect file-transfer and remote-execution functions to send a staged four-part VBScript loader to the connecting endpoint, potentially infecting technician and help-desk systems without further user interaction.
The payload chain profiles hosts, establishes persistence, seeks elevated execution, and can deploy remote-access, tunneling, and cryptocurrency-mining tools while attempting to evade security controls, including Microsoft Defender reporting and User Account Control. Huntress observed the activity at unrelated organizations during late-August incidents and advises organizations to reimage confirmed compromised systems, review ScreenConnect deployments and audit logs, and investigate suspicious Windows Script Host or PowerShell execution linked to ScreenConnect sessions.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ConnectWise advised partners to disable technician file-transfer permissions until an official fix is available. The mitigation can be applied immediately through ScreenConnect role settings without upgrading the product.
ConnectWise published an advisory acknowledging an issue in ScreenConnect file-transfer behavior affecting both cloud and on-premises deployments. The company said it intended to issue a CVE and an official fix within the following week.
In late August, Huntress observed malicious, unauthorized ConnectWise ScreenConnect installations across unrelated organizations. Attackers used social-engineering lures, including fake technical-support and refund scams, to get victims to grant remote access or run rogue installers.
Huntress recommended reimaging confirmed infected hosts from known-good media, reviewing ScreenConnect deployments and audit logs for Guest-process script execution, and investigating suspicious Windows Script Host or PowerShell activity. It also supplied indicators of compromise and said it was in direct contact with ConnectWise while monitoring the activity.
The modified clients executed a four-stage VBScript chain and transferred the scripts to systems connecting through incoming ScreenConnect sessions, enabling worm-like spread into technician or help-desk environments. Payload branches established persistence and could deploy elevated remote access, tunneling tools, and cryptocurrency miners while attempting security-product evasion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcecyberveille.ch
Open sourceinfosec.pub
Open sourcecybersecuritynews.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.