Hackers Abuse ScreenConnect and Quick Assist to Deploy Persistent Windows Backdoors
Brief
Threat actors are abusing legitimate remote-management tools, including ConnectWise ScreenConnect and Microsoft Quick Assist, to install persistent backdoors on Windows devices.
Huntress researchers identified several incidents in late August involving social-engineering lures, rogue ScreenConnect clients, VBScript payloads , and attempts to weaken endpoint defenses.
The campaigns affected unrelated organizations but followed a similar pattern. Victims were tricked into granting remote access or downloading a malicious ScreenConnect installer.
In one case, attackers posed as technical support staff and convinced a user to open Microsoft Quick Assist and share an access code. Another incident likely began with phishing, while a third used a fake Geek Squad refund lure.
