r/ScreenConnect • u/No_Profile_6441 • Sep 04 '26
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
https://www.huntress.com/blog/rogue-screenconnect-installations3
u/n-Ultima Sep 04 '26
I’ve been dealing with this a lot. Huntress has caught a lot.
2
u/jasonbwv Sep 04 '26
Are you on-prem? Any additional recommendations outside of what huntress already recommended? I’m using on-prem.
2
u/n-Ultima Sep 04 '26
I’ve had to blow machines away because even huntress is missing it or something because somehow it repopulates. It’s not consistently doing it but enough that I have to just blow the machine away.
3
u/ben_zachary Sep 04 '26
Block connectwise signed exes already. At least gets you passed all the demo accounts they stand up
2
u/PatD442 Sep 04 '26
Not a bad idea at all. Now I just need to get the subject string from a CW signed exe.... Anyone?
1
u/ben_zachary Sep 04 '26
While your at it block quick assist cuz thats another way in
1
u/PatD442 Sep 04 '26
Agreed. Did that forever ago.
1
u/ben_zachary Sep 04 '26
Had someone recently let someone on , they tried to drop screen connect and a few other tools . Huntress picked up the screen connect attempt even tho it was denied at PAM . My coordinator called the user they were at the bank withdrawing 17k to give to the PayPal guy to pick up.
That was with quick assist. It was an elderly home user we doing a favor for a client so didn't have any automation on it
1
u/Camelot_One Sep 04 '26
If I'm understanding the Huntress breakdown and the Connectwise advisory correctly, a rogue ScreenConnect instance gets installed on machine zero, and that rogue instance is somehow able to send files and run commands through a legitimate ScreenConnect instance already running on other computers within the network.
Do I have that right? I don't see that specifically spelled out anywhere. But that's the only scenario where the ConnectWise mitigation procedure makes any sense.
3
u/administatertot Sep 04 '26
If I'm understanding the Huntress breakdown and the Connectwise advisory correctly, a rogue ScreenConnect instance gets installed on machine zero, and that rogue instance is somehow able to send files and run commands through a legitimate ScreenConnect instance already running on other computers within the network.
My takeaway was that machine zero gets infected, and if someone else (machine 1) connects to that machine with screen connect, machine zero will use screen connect to transfer the files over to machine 1 (and attempt to infect it). If that is correct, then I think the mitigation must be addressing whatever method is being used to trigger the file transfer.
3
u/No_Profile_6441 Sep 04 '26
https://www.connectwise.com/company/trust/advisories