← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 3, 2026 · 09:54via CyberPress

Hackers Abuse ScreenConnect and Quick Assist to Deploy Persistent Windows Backdoors

Brief

Threat actors are abusing legitimate remote-management tools, including ConnectWise ScreenConnect and Microsoft Quick Assist, to install persistent backdoors on Windows devices.

Huntress researchers identified several incidents in late August involving social-engineering lures, rogue ScreenConnect clients, VBScript payloads , and attempts to weaken endpoint defenses.

The campaigns affected unrelated organizations but followed a similar pattern. Victims were tricked into granting remote access or downloading a malicious ScreenConnect installer.

In one case, attackers posed as technical support staff and convinced a user to open Microsoft Quick Assist and share an access code. Another incident likely began with phishing, while a third used a fake Geek Squad refund lure.

Read more on CyberPress