Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
- ID
- 22095
- Status
- summarized
- Published
- 07 Sep 2026, 7:36 PM
- Fetched
- 07 Sep 2026, 10:55 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 07 Sep 2026, 11:02 PM
- Tags
- Audience
- developerssaas_founders
What happened
Huntress disclosed worm-like activity abusing ConnectWise ScreenConnect, where rogue clients execute a four-stage VBScript chain (1.vbs through 4.vbs) on newly connected hosts. Three unrelated August 2026 incidents used different initial access methods—a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form—but all converged on rogue ScreenConnect clients contacting distinct C2 servers and launching VBScripts from the Temp directory.
Why it matters
If your team or MSP uses ScreenConnect for remote support, this is a concrete reason to audit which client instances are legitimate and block the named C2 endpoints (45.13.237[.]190, 131.123.40[.]98:8041, borertors92.anondns[.]net). The first-stage script specifically enumerates CrowdStrike, SentinelOne, Sophos, Huntress, and others before proceeding, so presence of an EDR alone is not a guarantee the chain stops.
Discussion angle
How social engineering plus a legitimate remote-access tool creates a worm-like propagation path—and whether your team's remote support workflow has any guardrails against rogue client installations.