ScreenConnect four-stage VBScript worm-like malware activity
Malware Activity
Summary
Hide ▲
Show ▼
A ScreenConnect-abusing malware activity is now using a four-stage VBScript chain to propagate infections to newly connected hosts, expanding reach and turning infected systems into delivery nodes. The activity matters because the chain can deploy backdoor, persistence, tunneling, and XMRig miner branches depending on host state. Researchers observed the behavior in August 2026 across multiple initial access paths, including Quick Assist, a phishing MSI installer, and a fake Geek Squad refund form.
Related Happenings
ValleyRAT malicious installer activity
Malware Activity
H score22
First: 02.09.2026 19:41
Last: 02.09.2026 19:41
Sources 1
About this happening:
ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
ValleyRAT malicious installer activity
Malware ActivityAbout this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
ScreenConnect remote access malware delivered through fake Bank of America phishing
Malware Activity
H score28
First: 05.08.2026 11:00
Last: 05.08.2026 11:00
Sources 1
About this happening:
A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk...
ScreenConnect remote access malware delivered through fake Bank of America phishing
Malware ActivityAbout this happening: A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk...
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score30
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityAbout this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Daxin and Stupig active on a Taiwan manufacturing host in 2026
Malware Activity
H score27
First: 16.07.2026 14:17
Last: 16.07.2026 14:17
Sources 1
About this happening:
The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...
Daxin and Stupig active on a Taiwan manufacturing host in 2026
Malware ActivityAbout this happening: The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
Latest development: 03.09.2026 13:43
KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.
Timeline
-
07.09.2026 14:36 2 articles · 3h ago
ScreenConnect four-stage VBScript worm-like malware activity
Initial DisclosureInitial access used Quick Assist, a phishing-delivered MSI installer, or a fake Geek Squad refund form to deploy rogue ScreenConnect and start the multi-stage VBScript chain.
Show sources
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts — thehackernews.com — 07.09.2026 14:36
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts — thehackernews.com — 07.09.2026 14:36