Bottom line: Security leaders should monitor ScreenConnect activity for suspicious behavior.
What's happening: A group of attackers is using compromised ScreenConnect clients to spread a worm-like malware campaign. The attackers are targeting users in the United States, using the compromised ScreenConnect clients to infect new clients. The attack is believed to have started in April 2022, with a total of 18 CVE-2020-12871 vulnerabilities exploited.
What to do: Security teams should implement an additional layer of monitoring and logging to detect and respond to potential attacks, and review the ScreenConnect client configuration to ensure that only trusted clients can connect.