SECURITY·중요도 7·2026. 09. 07.·The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

── KO ──────────────────

악성 VBScript를 새로운 시스템에 배포하는 ScreenConnect 악성 활동에 대한 연구 결과.

사이버 보안 연구자들이 ConnectWise ScreenConnect를 악용해 악성 Visual Basic Script (VBScript) 페이로드를 새로운 시스템에 배포하는 웜 같은 활동에 대한 세부 사항을 공개했습니다. Huntress에 따르면, 다양한 초기 접근 방법을 사용하는 세 건의 무관한 사건이 발견되었습니다. 이들은 기술 지원 사기, 피싱으로 배포된 MSI 설치 프로그램, 및 가짜 설치 프로그램을 포함합니다.


── EN ──────────────────

Details on worm-like activity using ScreenConnect to spread malicious VBScript payload to new systems.

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found using diverse initial access methods, including a tech-support scam, a phishing-delivered MSI installer, and a fake installation program.

원문 보기 →목록으로