AI Security AI安全 3h ago Updated 58m ago 更新于 58分钟前 40

Modified ScreenConnect Clients Used in Worm-Like Campaign 修改版ScreenConnect客户端被用于蠕虫式攻击活动

Modified ScreenConnect clients are being weaponized in a worm-like attack campaign since late August to propagate malicious payloads across connected endpoints The attack chain uses four VBScript files for reconnaissance, payload staging, and PowerShell execution, followed by a second PowerShell script that erases evidence, attempts UAC bypass, and installs a concealed rogue ScreenConnect client for lateral propagation Attackers gain initial access primarily through social engineering, including 修改过的ScreenConnect客户端被用于蠕虫式攻击活动,通过合法远程管理工具横向传播恶意载荷 攻击始于8月下旬,利用社会工程学诱导受害者运行Quick Assist,随后部署四个VBScript文件执行系统侦察、载荷暂存和PowerShell执行 攻击者通过User Run Key建立持久性,并安装UltraViewer远程桌面软件维持访问 ConnectWise已发布安全公告,建议管理员立即禁用ScreenConnect的文件传输功能,CVE和官方修复即将发布

62
Hot 热度
55
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • Modified ScreenConnect clients are being weaponized in a worm-like attack campaign since late August to propagate malicious payloads across connected endpoints
  • The attack chain uses four VBScript files for reconnaissance, payload staging, and PowerShell execution, followed by a second PowerShell script that erases evidence, attempts UAC bypass, and installs a concealed rogue ScreenConnect client for lateral propagation
  • Attackers gain initial access primarily through social engineering, including tech support impersonation via Windows Quick Assist and phishing, then establish persistence via User Run Keys and install UltraViewer remote desktop software
  • ConnectWise has acknowledged a file transfer vulnerability in ScreenConnect affecting both cloud and on-premises deployments, with a CVE and official fix expected soon
  • Huntress recommends administrators apply extra scrutiny to on-premises ScreenConnect installations and disable file transfer functionality as an immediate mitigation

Why It Matters

This campaign demonstrates how legitimate remote access tools can be subverted into worm-like propagation vectors, turning a single compromised endpoint into a gateway for widespread lateral movement within connected environments. For AI and security practitioners, it underscores the critical importance of monitoring for modified or unauthorized instances of trusted software and the need for zero-trust principles in remote support tool deployments.

Technical Details

  • The attack begins with social engineering (tech support impersonation via Quick Assist or phishing) to deploy a rogue ScreenConnect client on the victim machine
  • Once installed, the malicious client spawns repeated Windows Script Host (wscript.exe) child processes to deploy four VBScript files from the ScreenConnect temporary directory, designed for system reconnaissance, payload staging, and PowerShell execution
  • A second PowerShell script erases staging evidence, attempts UAC bypass, and installs a concealed ScreenConnect client that continuously monitors for new host connections to propagate the four-stage VBScript chain laterally
  • Persistence is established through a User Run Key registry entry pointing to an additional VBScript file, alongside installation of UltraViewer remote desktop software
  • ConnectWise confirmed a file transfer behavior vulnerability in ScreenConnect Remote Access Support and Access sessions affecting both cloud and on-premises deployments, with a CVE and patch forthcoming

Industry Insight

  • Organizations relying on on-premises ScreenConnect should immediately audit all installations, disable file transfer functionality until a patch is available, and monitor for unauthorized ScreenConnect processes or unexpected wscript.exe spawning
  • The worm-like propagation mechanism highlights the need for network segmentation and strict endpoint monitoring around remote access tools, as a single compromised machine can rapidly become a distribution node
  • This campaign reflects a growing trend of threat actors abusing legitimate remote support infrastructure for lateral movement; security teams should treat any unexpected remote access tool installation as a high-priority indicator of compromise and enforce application whitelisting where possible

TL;DR

  • 修改过的ScreenConnect客户端被用于蠕虫式攻击活动,通过合法远程管理工具横向传播恶意载荷
  • 攻击始于8月下旬,利用社会工程学诱导受害者运行Quick Assist,随后部署四个VBScript文件执行系统侦察、载荷暂存和PowerShell执行
  • 攻击者通过User Run Key建立持久性,并安装UltraViewer远程桌面软件维持访问
  • ConnectWise已发布安全公告,建议管理员立即禁用ScreenConnect的文件传输功能,CVE和官方修复即将发布

为什么值得看

这篇文章揭示了合法远程管理工具被恶意利用的最新攻击模式,对IT管理员和网络安全从业者具有重要警示意义。攻击者利用社会工程学结合技术漏洞的组合策略,展示了现代网络攻击的复杂性和隐蔽性。

技术解析

  • 攻击链分析:社会工程学→Quick Assist远程协助→安装恶意ScreenConnect→部署VBScript→系统侦察→载荷暂存→PowerShell执行→持久化建立→横向传播
  • 恶意脚本功能:四个VBScript文件分别负责系统信息收集、载荷下载、执行和清理痕迹,通过Windows Script Host (wscript.exe) 子进程执行
  • 持久化机制:攻击者通过注册表User Run Key和安装UltraViewer远程桌面软件实现长期访问,恶意ScreenConnect客户端持续检查新主机连接以传播载荷
  • 横向传播策略:利用ScreenConnect的合法远程连接功能,将恶意客户端传播到其他受管理的端点,形成蠕虫式扩散

行业启示

  • 远程管理工具的安全配置至关重要,管理员需要对On-premises部署的ScreenConnect应用额外审查,并考虑临时禁用文件传输功能
  • 社会工程学攻击仍然有效,需要加强员工安全意识培训,特别是针对远程协助工具的验证流程
  • 安全厂商需要快速响应并修复已知漏洞,ConnectWise的紧急公告和临时缓解措施展示了漏洞披露的最佳实践

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究