⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts Ravie LakshmananSep 07, 2026Malware / Vulnerability Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure, to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations. However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning "wscript.exe" to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The incidents were observed in August…