Modified ScreenConnect Clients Used in Worm-Like Campaign

Researchers found that the attackers are using backdoaded ScreenConnect instances to spread malware, infecting new clients.

Bottom line: Security leaders should monitor ScreenConnect activity for suspicious behavior.

What's happening: A group of attackers is using compromised ScreenConnect clients to spread a worm-like malware campaign. The attackers are targeting users in the United States, using the compromised ScreenConnect clients to infect new clients. The attack is believed to have started in April 2022, with a total of 18 CVE-2020-12871 vulnerabilities exploited.

What to do: Security teams should implement an additional layer of monitoring and logging to detect and respond to potential attacks, and review the ScreenConnect client configuration to ensure that only trusted clients can connect.

Source: SecurityWeek