The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

MalwareHighphishing

Attackers are exploiting compromised ScreenConnect clients to distribute a four-stage VBScript malware payload to newly connected systems. Initial compromise vectors include tech-support scams, phishing emails with MSI installers, and fake applications. This affects organizations using ScreenConnect and represents a significant supply-chain-like threat via remote access software.

AI summary · generated with Claude

https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html