CVE Tools

Attackers spread malware through ScreenConnect file transfers

Help Net SecurityBy Sinisa Markovic

Reported exploitedScreenConnect

Our summary

Threat actors are actively exploiting a file transfer vulnerability in ConnectWise ScreenConnect to distribute malware across remote access sessions. According to Huntress research, attackers deploy rogue client instances that spawn VBScript files to establish persistence and create a worm-like infection pattern on newly connected systems. This compromise affects both cloud-hosted and on-premise deployments. As a mitigation pending an official patch, ConnectWise advises administrators to disable file transfer permissions within their role settings.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store