Attackers use rogue ScreenConnect clients to spread malware

A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed.

ScreenConnect file transfer flaw

“A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory.

ScreenConnect is a popular remote support and access solution tailored for IT departments and managed service providers (MSPs). The platform can be hosted by ConnectWise (in their cloud) or self-hosted by organizations (on-prem or in their own private cloud).

Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians.

Administrators can do this by going to Administration > Security > Roles, editing each assigned role, and reviewing the permissions for each session group. If TransferFiles, or TransferFilesInSession on legacy versions, is enabled, it should be deselected. The change must be applied to each applicable role.

“This setting change does not require a version upgrade and can be applied immediately,” ConnectWise stated.

The advisory follows research from cybersecurity company Huntress describing how rogue ScreenConnect clients spread malware to every new machine that connects to them.

Every incident began with social engineering that led to rogue ScreenConnect instances being deployed on victims’ machines, something Huntress said is fairly typical, since “RMM abuse is a top attack vector” the company has tracked over the past year.

After the rogue instances landed, the clients began spawning repeated Windows Script Host processes, flagged as abnormal behavior, to deploy four VBScript files named 1.vbs through 4.vbs. Attackers were also seen creating a Windows registry Run Key named WindowsServiceHost, pointing to a matching script file in the affected user’s AppData directory.

“An analysis of the payloads used in the attack revealed a staged attack designed to profile hosts and conceal activity. Perhaps the most interesting part of the attack chain was that it used modified ScreenConnect clients to propagate the VBScript chain (specifically executing the four files (1.vbs to 4.vbs) to connected ScreenConnect endpoints, creating worm-like spread across newly connected systems,” the researchers noted.

The scripts were used for system discovery and to retrieve or launch additional components. Huntress documented payloads associated with persistence, additional ScreenConnect installations, tunneling, security-control changes, and cryptocurrency mining.

Huntress advises checking ScreenConnect audit logs for RunFiles or RanFiles entries tied to a guest process, and recommends reimaging any machine already showing signs of compromise from known-good media.

“From our conversations with ConnectWise and our current understanding of the risk, we suggest admins apply extra scrutiny to any on-premises ScreenConnect installations you may have within your environment,” Huntress added.

UPDATE (September 7, 2026, 08:45 a.m. ET):

ConnectWise has not confirmed a link between the file transfer flaw and the rogue ScreenConnect campaign Huntress described. This article has been edited to point that out.

UPDATE (September 11, 2026, 09:28 a.m. ET):

ConnectWise has fixed CVE-2026-84869, “a condition in the ScreenConnect client [that] may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.”

The vulnerability does not impact ScreenConnect servers, just versions prior to v26.6.5 of the ScreenConnect client.

“The ScreenConnect 26.6.5 patch includes updates to strengthen client and session handling for file-transfer and file-execution actions,” the vendor said, and advised organizations with on-premise ScreenConnect instances to ugrade them to the fixed version, then reinstall their host clients and update their access agents.

John Hammond, Senior Principal Security Researcher at Huntress, told Help Net Security that CVE-2026-84869 is what they believe the attackers are using in the incidents they observed.

“The activity we observed and outlined (modified ScreenConnect clients automatically transferring and executing files) aligns with the vulnerability disclosure and our coordination with ConnectWise,” he noted.

“If organizations follow the upgrades and instructions advised by ConnectWise, their ScreenConnect instances should not be susceptible to this attack. VBScript payloads should no longer execute and the patch should mitigate this risk.”

Don't miss