Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns
Huntress reports that hijacked ScreenConnect installations are propagating malware autonomously between hosts in a worm-like fashion, turning a trusted remote-support tool into an enterprise-wide lateral-movement vector.
Summary written by editorial AI · Source link below
Cybersecurity firm Huntress has uncovered a wave of malicious installations of ScreenConnect, a widely used remote-support tool, that spread between machines without any further action from a victim or an attacker, a self-propagating attack chain researchers likened to a computer worm. In a blog post published this week, Huntress said its Security Operations Center (SOC) […] The post Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns appeared first on IT Security G
Editorial Analysis
Self-propagating abuse of a widely deployed remote-support tool can spread across flat networks in minutes, making rapid containment and asset inventory essential.
Immediately audit all ScreenConnect deployments for signs of compromise, enforce network segmentation, and apply the vendor's latest security updates.
A widely used remote-support tool is being hijacked to spread malware automatically across networks — verify your installations are secure.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at IT Security Guru in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d