Hackers Are Hijacking Remote-Support Software to Spread Malware Across Whole Networks
A modified version of the popular IT tool ScreenConnect is being used in a self-spreading attack that starts with a fake tech-support call and ends with criminals inside your entire network.

Key points
- Criminals distributed tampered copies of ConnectWise ScreenConnect, a tool businesses use to let IT staff control computers remotely, beginning around 20 August 2025.
- The attack starts with social engineering, where someone calls or messages a victim pretending to be tech support, then tricks them into handing over access.
- Once inside one machine, the malware spreads itself automatically to every other device connected through ScreenConnect on the same network.
- ConnectWise has confirmed a flaw in ScreenConnect's file-transfer feature and advises administrators to disable that feature immediately while a formal fix is prepared.
- Security firm Huntress spotted the same attack pattern across multiple separate organisations within days.
Security researchers at Huntress have uncovered an attack campaign that turns a widely trusted remote-support tool against the very businesses that rely on it. The tool is ScreenConnect, made by ConnectWise, which IT teams use to connect to employees' computers and fix problems without being in the same room. Criminals have built modified, booby-trapped versions of it.
How do the hackers get in?
Every incident Huntress documented began the same way: a phone call or message from someone pretending to be technical support. In the 20 August attack, the criminal told the victim to open Quick Assist, a remote-access program built into Windows, which gave the attacker direct control of the machine. From there, the fake ScreenConnect client was installed and the damage began.
This is classic social engineering, meaning manipulation rather than technical trickery, and it is the front door for this entire campaign.
What happens after the fake software lands?
Fast damage. The rogue ScreenConnect client immediately launches four VBScript files, which are small automated scripts, from a temporary folder on the victim's computer.
Those scripts do four things in sequence: they quietly map out the infected machine, prepare hidden payloads, erase traces of the setup, and attempt a UAC bypass (a technique that tricks Windows into granting the attacker full administrator rights without asking the user for permission). A second hidden copy of ScreenConnect is then installed, which continuously checks for other devices connected to the network and pushes the same four-script chain to each one. That self-spreading behaviour is why researchers describe it as worm-like.
The criminals also install UltraViewer, another legitimate remote-desktop tool, giving themselves a backup route into the machine even if the original infection is spotted and removed.
| Event | Date | Detail |
|---|---|---|
| First confirmed attack | 20 August | Victim tricked via Quick Assist; five VBScript files executed |
| Second environment hit | 20 August | Same files, likely separate phishing attack |
| Third attack confirmed | 24 August | Same tools, same social-engineering starting point |
| ConnectWise advisory published | Late August | File-transfer flaw confirmed; fix pending |
Should ordinary employees and customers be worried?
Yes, if their employer uses ScreenConnect for IT support. Huntress observed the campaign spreading across multiple organisations, not just one. ConnectWise confirmed to SecurityWeek that a real flaw in ScreenConnect's file-transfer feature is involved, affecting both cloud-hosted and on-premises versions. A CVE identifier, the standard label assigned to a confirmed software vulnerability, had not been issued at time of publication, though ConnectWise said one would follow alongside an official patch.
Until that patch arrives, ConnectWise recommends that IT administrators disable file-transfer functionality inside ScreenConnect entirely. Huntress adds that any on-premises ScreenConnect installation deserves extra scrutiny right now.
If someone calls you claiming to be IT support and asks you to install anything or hand over remote access, verify their identity through a channel your company already uses, such as an internal directory number, before clicking anything.



