Find notable cyber news and cases, enriched with sources, timelines, and signals.

ScreenConnect four-stage VBScript worm-like malware activity

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

A ScreenConnect-abusing malware activity is now using a four-stage VBScript chain to propagate infections to newly connected hosts, expanding reach and turning infected systems into delivery nodes. The activity matters because the chain can deploy backdoor, persistence, tunneling, and XMRig miner branches depending on host state. Researchers observed the behavior in August 2026 across multiple initial access paths, including Quick Assist, a phishing MSI installer, and a fake Geek Squad refund form.

Related Happenings

ValleyRAT malicious installer activity

Malware Activity
H score22 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

About this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...

ScreenConnect remote access malware delivered through fake Bank of America phishing

Malware Activity
H score28 First: 05.08.2026 11:00 Last: 05.08.2026 11:00 Sources 1

About this happening: A fake Bank of America phishing chain now delivers ScreenConnect RMM to Windows victims, creating remote access, privilege escalation, and C2 connectivity risk...

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
H score30 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...

Daxin and Stupig active on a Taiwan manufacturing host in 2026

Malware Activity
H score27 First: 16.07.2026 14:17 Last: 16.07.2026 14:17 Sources 1

About this happening: The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...

Latest development: 03.09.2026 13:43

KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.

Timeline

  1. 07.09.2026 14:36 2 articles · 3h ago

    ScreenConnect four-stage VBScript worm-like malware activity

    Initial Disclosure

    Initial access used Quick Assist, a phishing-delivered MSI installer, or a fake Geek Squad refund form to deploy rogue ScreenConnect and start the multi-stage VBScript chain.

    Show sources