ScreenConnect Clients Are Spreading Scripts Across Hosts

Huntress saw rogue ConnectWise ScreenConnect clients in several customer environments during late August repeatedly spawn Windows Script Host and run four VBScript files across unrelated hosts. On September 3, ConnectWise acknowledged an issue in ScreenConnect file-transfer behavior and said a CVE and official fix will follow within the week. The pattern matters because the ScreenConnect client itself appears to hand off script files through Windows Script Host, so the trusted remote-support channel can become the way payloads move and run on other machines. Huntress also saw attacker-created Run keys pointing to a VBScript in user AppData, which fits a staged attempt to keep activity going while hiding it. For organizations that use ScreenConnect alongside other remote-management tools, the exposure is not limited to one compromised endpoint: a single foothold can become a path for script execution elsewhere in the same RMM footprint. If the file-transfer path is what makes the spread possible, cleaning only the first machine may leave the propagation mechanism intact.

Part of the PlainSec briefing for 2026-09-03

Editions

Sources