Ethical Hacking News
A recent vulnerability in the ConnectWise ScreenConnect remote access tool has been exploited by malicious actors to distribute a highly sophisticated four-stage Visual Basic Script (VBScript) payload to newly connected systems. The worm-like activity has been identified in three unrelated incidents, each using diverse initial access methods, and has been found to spread rapidly across newly connected systems, creating a significant threat to system security.
A recent vulnerability in ConnectWise ScreenConnect has been exploited to distribute a sophisticated four-stage VBScript payload. The malware payload, dubbed a "four-stage VBScript chain," spreads rapidly across newly connected systems, creating a worm-like behavior. The attack uses diverse initial access methods, such as Quick Assist tech-support scams, phishing-delivered MSI installers, and fake Geek Squad refund form lures. The malware payload has been detected in various stages, including payloads that lead to a user-level ScreenConnect backdoor, privilege escalation, and tunneling utilities. ConnectWise has issued an advisory, recommending customers disable file transfer in ScreenConnect sessions and re-image affected hosts. The incident highlights the importance of vulnerability management, cybersecurity awareness, and staying up-to-date with security patches and updates. The attack demonstrates the creativity and sophistication of modern malware, using tactics and techniques to evade detection and achieve malicious goals.
A recent vulnerability in the ConnectWise ScreenConnect remote access tool has been exploited by malicious actors to distribute a highly sophisticated four-stage Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, a cybersecurity company, the worm-like activity has been identified in three unrelated incidents, each using diverse initial access methods, such as Quick Assist tech-support scams, phishing-delivered MSI installers, and fake Geek Squad refund form lures.
The malware payload, which has been dubbed a "four-stage VBScript chain," is designed to spread rapidly across newly connected systems, creating a worm-like behavior that propagates infections over new ScreenConnect connections. Once the ScreenConnect instance is installed, the malware launches the four VBScript files, which follow a specific sequence of actions to achieve their malicious goals.
The first stage of the payload, denoted as "1.vbs," profiles the host, checks system resources, verifies if ScreenConnect is installed, enumerates security products, and writes the results to "%TEMP%\value.txt" in the form of a three-bit state variable. The second stage, "2.vbs," waits for the "%TEMP%\value.txt" file and checks for the presence of the word "abort." If the word does not exist, it downloads a file from Dropbox, decodes its contents, and writes them to "%TEMP%\map.txt." The third stage, "3.vbs," works similarly to 2.vbs, waiting for "%TEMP%\map.txt" and then proceeding to download the relevant file from the Dropbox link specified in the text file based on the state values set by 1.vbs in "%TEMP%\value.txt." The fourth stage, "4.vbs," waits for the presence of the downloaded "%TEMP%\out.enc" payload and launches a PowerShell script ("%TEMP%\runner.ps1") to decrypt the contents of "%TEMP%\out.enc," write them to "%APPDATA%\Microsoft\Windows\Templates\Classic\sys_cache.zip," and execute a second-stage PowerShell script ("PyTorchFix.ps1").
The attack sequence is designed to exploit the vulnerabilities of the ScreenConnect tool, which is widely used in the remote access and monitoring industry. The malware payloads have been detected in various stages, including payloads that lead to a user-level ScreenConnect backdoor, privilege escalation via a User Account Control (UAC) bypass and persistence, and tunneling utilities and a cryptocurrency miner.
In response to the findings, ConnectWise has issued an advisory, stating that it has identified an issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The company recommends that customers mitigate the risk by disabling the ability for technicians to transfer files. Huntress has also recommended that affected hosts be re-imaged from known-good media or a clean operating system install.
The incident highlights the importance of vulnerability management and the need for organizations to stay up-to-date with the latest security patches and updates. It also underscores the need for cybersecurity professionals to be vigilant and proactive in monitoring their systems for signs of malicious activity.
The attack also demonstrates the creativity and sophistication of modern malware, which can use various tactics and techniques to evade detection and achieve their malicious goals. The use of a four-stage VBScript chain, which is designed to spread rapidly across newly connected systems, is a particularly insidious tactic that can be difficult to detect and mitigate.
In conclusion, the recent vulnerability in the ConnectWise ScreenConnect tool has highlighted the importance of cybersecurity awareness and the need for organizations to stay vigilant in protecting their systems from malicious activity. The use of a four-stage VBScript chain to spread malware infections across newly connected systems is a sophisticated tactic that requires prompt attention and action.
Related Information:
https://www.ethicalhackingnews.com/articles/Rogue-ScreenConnect-Clients-Spread-Four-Stage-VBScript-Chain-Creating-Worm-Like-Malware-Infections-ehn.shtml
https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
https://utopiats.com/blog/rogue-screenconnect-clients-spread-four-stage-vbscript-chain-to-newly-connected-hosts
Published: Mon Sep 7 08:43:10 2026 by llama3.2 3B Q4_K_M