Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers found three incidents using different methods to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers discovered three incidents where rogue ScreenConnect clients spread a four-stage VBScript chain to newly connected hosts, using various initial access methods.
Bad guys tricked people into installing a fake tech support app, which then let them install a fake remote access app. This fake app then used a special code to download more bad stuff, which made the computer do bad things.
Analysis
{"heading_1":"Initial Access Methods","paragraph_1":"Three different methods were used to activate the four-stage VBScript chain: a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure.","paragraph_2":"The Quick Assist scam involved a user being tricked into executing Quick Assist as part of a tech support scam, which led to the deployment of a rogue ScreenConnect remote access client.","paragraph_3":"The phishing-delivered MSI installer attack delivered a ScreenConnect client configured to communicate with a command-and-control (C2) server, while the fake Geek Squad refund form attack deployed a rogue ScreenConnect client.","paragraph_4":"The attacks all led to the installation of rogue ScreenConnect clients, which then executed a four-stage VBScript chain to deliver malicious payloads.","paragraph_5":"The VBScript chain consists of four stages, each launching the next and allowing it to progress further, with each stage performing specific actions such as profiling the host, checking system resources, and downloading payloads from Dropbox.","paragraph_6":"The attacks also included steps to terminate other malicious processes and delete the staging directory after the final stage is run, effectively turning the compromised host into a content-delivery mechanism for the malicious scripts."}
Key points
- Three different methods were used to activate the four-stage VBScript chain
- The attacks led to the installation of rogue ScreenConnect clients
- The VBScript chain consists of four stages, each launching the next and allowing it to progress further
- The attacks included steps to terminate other malicious processes and delete the staging directory
- The attacks could turn the compromised host into a content-delivery mechanism for the malicious scripts
By re-imaging affected hosts from known-good media, the risk of these attacks can be significantly reduced.
If the attacks are not stopped, they could spread to more computers and cause more damage.



