Modified ScreenConnect Clients in Worm-Like Malware Campaign: Cybersecurity Threat

www.news4hackers.com-modified-screenconnect-clients-in-worm-like-malware-campaign-cybersecurity-threat-modified-screenconnect-clients-in-worm-like-malware-campaign-cybersecurity-threat

Modified ScreenConnect clients are being used in a worm-like attack to distribute malicious payloads across connected systems.

Attack Overview

Modified ScreenConnect clients are being leveraged in a worm-like attack campaign to distribute malicious payloads across connected systems, according to cybersecurity firm Huntress. The campaign, detected in late August, initiates with compromised ScreenConnect instances installed on victim machines through social engineering tactics. Once deployed, these malicious clients generate multiple instances of the Windows Script Host (wscript.exe) process to execute four VBScript files.

Initial Compromise and Payload Execution

Huntress identified a consistent pattern across multiple organizations where the rogue ScreenConnect clients facilitated lateral movement by propagating payloads to other connected instances. Attackers also established persistence by creating a User Run Key pointing to an additional VBScript file.

Specific Incidents

On August 20, a threat actor impersonating technical support directed a victim to use the Windows Quick Assist remote support tool, granting unauthorized access to the system. The attacker then executed five VBScript files before the intrusion was halted. The same VBScript files were later observed in a separate environment, suggesting a coordinated phishing effort.

Technical Details and Propagation

The rogue ScreenConnect client immediately launched the four VBScript files from its temporary directory. Network telemetry revealed active connections from ScreenConnect to multiple remote IP addresses during the investigation. The attacker also utilized the User Run Key for persistence and installed UltraViewer, a remote desktop application.

August 24 Attack

A similar attack occurred on August 24, beginning with social engineering. The four VBScript files deployed by the malicious ScreenConnect clients performed system reconnaissance, prepared payloads, and executed a PowerShell script. This code triggered a secondary PowerShell script that deleted staging evidence, attempted to bypass User Account Control (UAC), and installed a concealed ScreenConnect client. This client continuously monitored for new host connections to propagate the four-stage VBScript chain to other ScreenConnect endpoints.

Responses and Mitigation

Huntress advised administrators to scrutinize on-premises ScreenConnect installations, citing risks associated with the compromised software. ConnectWise, the developer of ScreenConnect, issued an advisory regarding an issue affecting file transfer behavior in its Remote Access Support and Access sessions. The vulnerability impacts both cloud and on-premises deployments and is expected to receive a CVE identifier within the week, along with a patch. Until then, administrators are urged to disable file transfer functionality in ScreenConnect to mitigate risks.

Huntress emphasized the importance of monitoring for unusual network activity, such as unexpected connections from ScreenConnect to external IP addresses, and reviewing registry entries for persistence mechanisms like the User Run Key. The incident also underscores the need for organizations to verify the integrity of remote access software and implement strict access controls to prevent unauthorized deployments.

Key Takeaways

The campaign highlights the exploitation of remote access tools for lateral movement and persistence. Attackers leveraged social engineering to gain initial access, followed by script-based payloads to execute reconnaissance, stage malicious activities, and maintain control. The use of VBScript and PowerShell underscores the reliance on native system tools to evade detection. The integration of UltraViewer and the automated propagation mechanism demonstrate a sophisticated approach to expanding the attack surface across connected networks.



About Author

en_USEnglish