Researchers Identify Worm-Like Campaign Targeting ConnectWise ScreenConnect
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — Cybersecurity researchers have disclosed details of a sophisticated worm-like campaign exploiting ConnectWise ScreenConnect, a widely used remote support and screen-sharing application, to distribute malicious payloads across global networks. The activity, identified by Huntress and other security analysts on Monday, marks a significant evolution in how attackers leverage legitimate administrative tools for automated lateral movement.
The malware operates by injecting a malicious Visual Basic Script (VBScript) payload onto systems immediately after they establish a connection through the compromised ScreenConnect instance. Once executed, the script appears designed to replicate itself, seeking out other connected devices within the same network environment to propagate without further user interaction. This worm-like behavior distinguishes the campaign from standard ransomware or data exfiltration attacks, which typically require manual execution or specific trigger events.
ConnectWise ScreenConnect is a critical tool for IT administrators and managed service providers, enabling remote troubleshooting and support. By compromising this software, attackers gain a trusted foothold within corporate environments, allowing them to bypass traditional perimeter defenses. The campaign has been observed targeting newly connected systems, suggesting the malware is actively scanning for fresh entry points to maximize its spread.
Huntress, a cybersecurity firm specializing in endpoint detection and response, highlighted the technical mechanics of the attack in a public advisory. The firm noted that the VBScript payload executes silently, making detection difficult for organizations relying solely on signature-based antivirus solutions. The global nature of the campaign indicates that no specific region or industry is currently immune, with potential victims spanning various sectors that utilize remote support infrastructure.
Security experts warn that the rapid propagation capability of this worm-like activity could lead to widespread infection if left unchecked. Unlike previous incidents where attackers manually moved between systems, this automated approach allows for exponential growth in compromised devices within a short timeframe. The speed at which the malware can traverse a network increases the likelihood of critical infrastructure being affected before defenders can isolate the threat.
While the technical details of the payload and the specific methods used to initially compromise the ScreenConnect servers have been outlined, the ultimate objective of the campaign remains unclear. Researchers have not yet determined whether the primary goal is data theft, ransomware deployment, or the creation of a large-scale botnet for future operations. The identity of the threat actors behind the attack has also not been disclosed.
As organizations rush to patch vulnerabilities and update their remote access protocols, investigators continue to monitor the situation for new variants or changes in behavior. The emergence of this worm-like activity underscores the growing risk posed by supply chain attacks targeting widely adopted IT management tools. Until the full scope of the campaign is understood, cybersecurity professionals advise heightened vigilance and immediate isolation of any systems exhibiting unusual script execution patterns.