TI Mindmap HUB
Threat Intelligence Report

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

๐Ÿ“… September 8, 2026 ๐Ÿ“ฐ www.huntress.com ๐Ÿ” 0 CVE(s) referenced

A sophisticated, worm-like attack is abusing rogue ScreenConnect installations to automatically spread multi-stage VBScript payloads across unrelated organizations, enabling persistent remote access, evasion, and even cryptomining, while leveraging legitimate RMM tools and exploiting file transfer features.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle