Hackers Weaponize ScreenConnect to Spread Worm-Like Malware Across Windows Systems
Brief
Hackers are turning rogue remote-support installations into a tool that can spread malicious code between Windows computers.
The activity stands out because an infected remote-access client can pass staged payloads to connected systems, widening an intrusion without a lure for every victim.
The campaign began with social engineering, including fake technical-support interactions, phishing, and a fraudulent refund search. Victims granted remote access or ran an installer, letting attackers place an unauthorized client on the device.
The approach uses trust and normal support workflows, not a software flaw. Huntress researchers identified the pattern across unrelated organizations during critical incidents in late August.
