CVE Tools
Back to feed
Exploited in the wild ScreenConnect malware ConnectWise phishing

Attackers spread malware through ScreenConnect file transfers

Help Net Security·By Sinisa Markovic··2 min read
CVE Tools coverage

Threat actors are actively exploiting a file transfer vulnerability in ConnectWise ScreenConnect to distribute malware across remote access sessions. According to Huntress research, attackers deploy rogue client instances that spawn VBScript files to establish persistence and create a worm-like infection pattern on newly connected systems. This compromise affects both cloud-hosted and on-premise deployments. As a mitigation pending an official patch, ConnectWise advises administrators to disable file transfer permissions within their role settings.