How Attackers Exploit ScreenConnect File Transfers to Spread Malware
Attackers exploit vulnerabilities in ScreenConnect file transfer mechanisms to deploy malicious payloads
Critical Flaw in ScreenConnect File Transfer Mechanisms
According to ConnectWise, a critical flaw in the file transfer functionality of ScreenConnect Remote Access Support and Access sessions impacts both cloud-based and on-premises deployments. The company confirmed a CVE identifier will be released within the week, as outlined in its September 3 advisory.
According to ConnectWise, a critical flaw in the file transfer functionality of ScreenConnect Remote Access Support and Access sessions impacts both cloud-based and on-premises deployments. The company confirmed a CVE identifier will be released within the week, as outlined in its September 3 advisory.
ScreenConnect serves as a widely used remote support and access platform for IT departments and managed service providers (MSPs), offering cloud hosting through ConnectWise or self-hosted options for organizations.
Attack Chain Details
Research from cybersecurity firm Huntress revealed that malicious actors deploy rogue ScreenConnect clients to infect systems, leveraging social engineering tactics to establish compromised instances on victim machines. This method aligns with trends observed over the past year, where remote monitoring and management (RMM) tools are frequently abused as attack vectors.
Research from cybersecurity firm Huntress revealed that malicious actors deploy rogue ScreenConnect clients to infect systems, leveraging social engineering tactics to establish compromised instances on victim machines. This method aligns with trends observed over the past year, where remote monitoring and management (RMM) tools are frequently abused as attack vectors.
Once deployed, these rogue clients generate abnormal Windows Script Host processes to execute four VBScript files (1.vbs through 4.vbs). Attackers also create a Windows registry Run Key named WindowsServiceHost, linking it to a corresponding script file stored in the user’s AppData directory.
The attack chain involves a multi-stage process designed to gather system information and obscure malicious activity. Researchers noted that modified ScreenConnect clients are used to propagate the VBScript payload across connected endpoints, enabling a worm-like spread to newly joined systems.
The scripts facilitate system reconnaissance and trigger additional components, including persistence mechanisms, supplementary ScreenConnect installations, network tunneling, security configuration changes, and cryptocurrency mining operations.
Mitigation and Recommendations
ConnectWise has advised administrators to disable file transfer capabilities for technicians as a temporary mitigation. This can be achieved by navigating to Administration > Security > Roles, editing assigned roles, and removing permissions for TransferFiles or TransferFilesInSession on legacy versions. The adjustment applies to all relevant roles and does not require a software update.
Huntress further recommends inspecting ScreenConnect audit logs for anomalies tied to guest processes, such as RunFiles or RanFiles entries, and reimaging compromised systems using trusted sources.
The firm emphasized heightened vigilance for on-premises ScreenConnect deployments, citing their increased exposure to targeted attacks. Organizations are urged to monitor for suspicious activity and apply recommended security measures promptly.
The firm emphasized heightened vigilance for on-premises ScreenConnect deployments, citing their increased exposure to targeted attacks. Organizations are urged to monitor for suspicious activity and apply recommended security measures promptly.
Conclusion
Organizations are urged to monitor for suspicious activity and apply recommended security measures promptly.
