π¨ Rogue ScreenConnect clients are triggering worm-like VBScript spread across new host connections.
The 4-stage chain can deliver a backdoor, UAC bypass tooling, or a cryptominer based on host state. ConnectWise recommends disabling file transfers until a fix is available.
How the propagation works: https://t.co/iKWpzkqj6V