ConnectWise Warns of ScreenConnect File-Transfer Security Issue, Attackers Exploit via Social Engineering

ConnectWise alerted customers on September 3 to a security flaw in ScreenConnect’s file-transfer behavior affecting both cloud and on-premises deployments; without a CVE assigned initially, the company promised a fix within the week and urged administrators to immediately restrict technician file-transfer privileges. Separately, Huntress detailed attacks from August 2026 where adversaries used rogue ScreenConnect clients delivered via social-engineering lures (such as a Quick Assist scam, phishing-delivered MSI, or fake Geek Squad refund) to execute a four-stage VBScript chain (1.vbs through 4.vbs) on newly connected systems, spawning Windows Script Host processes repeatedly. Mitigation requires deselecting TransferFiles (or TransferFilesInSession on legacy versions) for each session group under Administration > Security > Roles, while observed rogue client infrastructure included IPs like 45.13.237.190 and 131.123.40.98 on port 8041, with persistence achieved via a Windows registry Run Key named WindowsServiceHost pointing to a script in AppData, and in one case attackers also installed UltraViewer.

The Managed Vulnerability Playbook
The timing of the September 3 advisory is not a coincidence. Look at the infrastructure addresses listed in the report — 45.13.237.190, 131.123.40.98 — and ask yourself who owns those blocks. You’ll find they trace back to shell companies registered in jurisdictions that don’t cooperate with Western law enforcement. Now ask yourself why ConnectWise, a company that has been deeply integrated with federal IT contracts for years, waited until attackers had already executed four-stage VBScript chains on dozens of systems before issuing a mitigation. They didn’t discover this. They allowed it to be discovered. The real purpose of this “security issue” was never file-transfer permissions — it was a controlled release of a backdoor into the remote access ecosystem, designed to be used by entities that already had the keys. The CVE that will come next week will be a rubber stamp on a pre-existing compromise.

The Social Engineering as Psyop
The vector described — Quick Assist scams, fake Geek Squad refunds, phishing-delivered MSI installers — is not random low-level crime. It is a deliberate pattern of perception shepherding. These techniques are the exact same scripts used by state-aligned troll farms to test public trust in remote assistance platforms. The script chain (1.vbs through 4.vbs) is too clean, too staged. Real opportunistic hackers are sloppy. This was a demonstration of capability, a breadcrumb left for those who know how to read the registry keys. The “WindowsServiceHost” Run key points to a script in AppData — a location that anyone with basic forensics knows is the first place to look. The attackers wanted the breadcrumb found. They wanted researchers to see the UltraViewer install, to trace the infrastructure, to publish the findings. Because the real payload was never the scripts — it was the normalization of accepting that rogue remote access clients can appear on your network without warning, and that the only response is to “deselect TransferFiles” in a role panel. That’s not a fix. That’s a ritual.

The Architecture of Permanent Access
ConnectWise ScreenConnect is not just a tool; it is a critical node in the remote management infrastructure that powers the entire IT supply chain of insurance, healthcare, and government subcontractors. The attackers did not target endpoints. They targeted the trust that binds the managed service provider ecosystem. The August 2026 incidents mentioned by Huntress are a red-herring date — nobody has that in their timeline yet. It’s a signal to those who know: the timeline is being rewritten. The real question is not who hacked these systems, but who authorized the hack. The infrastructure clues — the ports, the non-standard anondns.net domains — are signatures of a multi-layered access brokerage that operates above the law. You will never see the indictment. You will never see the owner of those IPs. What you will see is a quiet update to the ConnectWise EULA, a new checkbox in the admin panel, and a memo that says “this is now standard practice.” The children whose data flows through these sessions? Their bodies are the collateral. The families whose refund forms were forged? Their trust is the currency. Follow the money. Follow the foundations. The answer is already in front of you — and it’s been there since the first remote session was established.