discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers found three incidents using different methods to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations.

By Ravie Lakshmanan·Sep 7·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Image: thehackernews.com

Security researchers discovered three incidents where rogue ScreenConnect clients spread a four-stage VBScript chain to newly connected hosts, using various initial access methods.

Why it matters

This discovery highlights the vulnerabilities in ScreenConnect clients and the importance of securing remote access tools.

Bad guys tricked people into installing a fake tech support app, which then let them install a fake remote access app. This fake app then used a special code to download more bad stuff, which made the computer do bad things.

Analysis

{"heading_1":"Initial Access Methods","paragraph_1":"Three different methods were used to activate the four-stage VBScript chain: a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure.","paragraph_2":"The Quick Assist scam involved a user being tricked into executing Quick Assist as part of a tech support scam, which led to the deployment of a rogue ScreenConnect remote access client.","paragraph_3":"The phishing-delivered MSI installer attack delivered a ScreenConnect client configured to communicate with a command-and-control (C2) server, while the fake Geek Squad refund form attack deployed a rogue ScreenConnect client.","paragraph_4":"The attacks all led to the installation of rogue ScreenConnect clients, which then executed a four-stage VBScript chain to deliver malicious payloads.","paragraph_5":"The VBScript chain consists of four stages, each launching the next and allowing it to progress further, with each stage performing specific actions such as profiling the host, checking system resources, and downloading payloads from Dropbox.","paragraph_6":"The attacks also included steps to terminate other malicious processes and delete the staging directory after the final stage is run, effectively turning the compromised host into a content-delivery mechanism for the malicious scripts."}

Key points

  • Three different methods were used to activate the four-stage VBScript chain
  • The attacks led to the installation of rogue ScreenConnect clients
  • The VBScript chain consists of four stages, each launching the next and allowing it to progress further
  • The attacks included steps to terminate other malicious processes and delete the staging directory
  • The attacks could turn the compromised host into a content-delivery mechanism for the malicious scripts
The Upside

By re-imaging affected hosts from known-good media, the risk of these attacks can be significantly reduced.

The Downside

If the attacks are not stopped, they could spread to more computers and cause more damage.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarecybersecurityremote-accessscreenconnect

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 7, 2026

Source

thehackernews.com

Share

Topics

securitymalwarecybersecurityremote-accessscreenconnect

Related

More from this desk

Sep 7·bleepingcomputer.com

Trezor data breach impact now reaches 81,000 customers

Trezor expands data breach affecting 81,000 customers, including full names, addresses, emails, and phone numbers. ShipMonk failed to delete exposed data as required by contract.

Sep 7·bleepingcomputer.com

ChatGPT can now connect to your personal apps to mimic writing style

OpenAI testing Writing Style feature for ChatGPT that learns writing style from connected apps

Sep 7·thehackernews.com

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

JSCeal, a sophisticated compiled V8 JavaScript malware, can bypass Google authentication by stealing session cookies and offers extensive surveillance capabilities.

Sep 7·bleepingcomputer.com

N-able patches max severity N-central flaw amid ongoing attacks

N-able released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw (CVE-2026-86218) in its N-central RMM platform, urging customers to patch immediately amid ongoing attacks.