The rogue ScreenConnect clients infect the hosts that connect to them
2026-09-08Security
Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.