{"id":617137,"date":"2026-09-07T11:02:13","date_gmt":"2026-09-07T11:02:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/617137\/"},"modified":"2026-09-07T11:02:13","modified_gmt":"2026-09-07T11:02:13","slug":"attackers-spread-malware-through-screenconnect-file-transfers","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/617137\/","title":{"rendered":"Attackers spread malware through ScreenConnect file transfers"},"content":{"rendered":"<p>A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/09\/connectwise-650.webp\" class=\"aligncenter\" alt=\"CVE-2024-1709 exploited\" title=\"ConnectWise ScreenConnect\"\/><\/p>\n<p>\u201cA CVE identifier and an official fix will be issued within the week,\u201d the company <a href=\"https:\/\/www.connectwise.com\/company\/trust\/advisories\" target=\"_blank\" rel=\"nofollow noopener\">wrote<\/a> in its September 3 advisory.<\/p>\n<p>ScreenConnect is a popular remote support and access <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/05\/fake-bank-of-america-email-account-guard\/\" rel=\"nofollow noopener\" target=\"_blank\">solution<\/a> tailored for IT departments and managed service providers (MSPs). The platform can be hosted by ConnectWise (in their cloud) or self-hosted by organizations (on-prem or in their own private cloud).<\/p>\n<p>The advisory follows research from cybersecurity company Huntress describing how rogue ScreenConnect clients spread malware to every new machine that connects to them.<\/p>\n<p>Every incident began with <a href=\"https:\/\/www.helpnetsecurity.com\/2025\/05\/06\/social-engineering-human-behavior\/\" rel=\"nofollow noopener\" target=\"_blank\">social engineering<\/a> that led to rogue ScreenConnect instances being deployed on victims\u2019 machines, something Huntress said is fairly typical, since \u201cRMM abuse is a top attack vector\u201d the company has tracked over the past year.<\/p>\n<p>After the rogue instances landed, the clients began spawning repeated Windows Script Host processes, flagged as abnormal behavior, to deploy four VBScript files named 1.vbs through 4.vbs. Attackers were also seen creating a Windows registry Run Key named WindowsServiceHost, pointing to a matching script file in the affected user\u2019s AppData directory.<\/p>\n<p>\u201cAn analysis of the payloads used in the attack revealed a staged attack designed to profile hosts and conceal activity. Perhaps the most interesting part of the attack chain was that it used modified ScreenConnect clients to propagate the VBScript chain (specifically executing the four files (1.vbs to 4.vbs) to connected ScreenConnect endpoints, creating worm-like spread across newly connected systems,\u201d the researchers noted.<\/p>\n<p>The scripts were used for system discovery and to retrieve or launch additional components. Huntress documented payloads associated with persistence, additional ScreenConnect installations, tunneling, security-control changes, and cryptocurrency mining.<\/p>\n<p>Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians.<\/p>\n<p>Administrators can do this by going to Administration &gt; Security &gt; Roles, editing each assigned role, and reviewing the permissions for each session group. If TransferFiles, or TransferFilesInSession on legacy versions, is enabled, it should be deselected. The change must be applied to each applicable role.<\/p>\n<p>\u201cThis setting change does not require a version upgrade and can be applied immediately,\u201d ConnectWise stated.<\/p>\n<p>Huntress advises checking ScreenConnect audit logs for RunFiles or RanFiles entries tied to a guest process, and recommends reimaging any machine already showing signs of compromise from known-good media.<\/p>\n<p>\u201cFrom our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,\u201d Huntress <a href=\"https:\/\/www.huntress.com\/blog\/rogue-screenconnect-installations\" target=\"_blank\" rel=\"nofollow noopener\">added<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments,&hellip;\n","protected":false},"author":2,"featured_media":617138,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[261919,61,60,46977,44298,261920,55157,80,30039],"class_list":["post-617137","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-connectwise","tag-ie","tag-ireland","tag-malware","tag-remote-access","tag-remote-management","tag-social-engineering","tag-technology","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/617137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=617137"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/617137\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/617138"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=617137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=617137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=617137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}