ScreenConnect Rogue Clients Turn Support Into Spread
Huntress and ConnectWise said rogue ScreenConnect clients are using a file-transfer flaw in ScreenConnect Remote Access, Support, and Access sessions to spread malware to every machine that later connects. ConnectWise said the issue affects both Cloud and on-prem deployments and that a CVE identifier and fix will be issued within the week.
The attack starts when an attacker plants a fake ScreenConnect client on one host, then uses later support sessions to push scripts and other payloads onto new connecting systems. That makes the remote-support link itself the delivery path, so the original foothold can keep infecting later endpoints instead of staying contained to one victim machine.
For organizations that run ScreenConnect as a live support channel, the exposure follows the workflow, not just the first compromised endpoint. If file transfer and related session permissions stay open, a rogue instance can keep widening the incident until it is removed from the environment.