AI Weekly Malaysia

Back to items Summaries

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

ID
22095
Status
summarized
Published
07 Sep 2026, 7:36 PM
Fetched
07 Sep 2026, 10:55 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
07 Sep 2026, 11:02 PM
Tags
Audience
developerssaas_founders

What happened

Huntress disclosed worm-like activity abusing ConnectWise ScreenConnect, where rogue clients execute a four-stage VBScript chain (1.vbs through 4.vbs) on newly connected hosts. Three unrelated August 2026 incidents used different initial access methods—a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form—but all converged on rogue ScreenConnect clients contacting distinct C2 servers and launching VBScripts from the Temp directory.

Why it matters

If your team or MSP uses ScreenConnect for remote support, this is a concrete reason to audit which client instances are legitimate and block the named C2 endpoints (45.13.237[.]190, 131.123.40[.]98:8041, borertors92.anondns[.]net). The first-stage script specifically enumerates CrowdStrike, SentinelOne, Sophos, Huntress, and others before proceeding, so presence of an EDR alone is not a guarantee the chain stops.

Discussion angle

How social engineering plus a legitimate remote-access tool creates a worm-like propagation path—and whether your team's remote support workflow has any guardrails against rogue client installations.

Top