First Seen: August 20, 2026
Malware: XMRig cryptominer
Affected Product: ConnectWise ScreenConnect client
Impact: ConnectWise ScreenConnect, a remote support and access platform widely used by MSPs and IT teams, is affected by a critical client-side vulnerability (CVE-2026-84869) in which missing authorization and improper privilege management in file-transfer handling allow a Guest in an active session to transfer and execute files on the Host without confirmation; servers are unaffected, but all clients prior to 26.6.5 are vulnerable and must be reinstalled or redeployed. Exploitation has been observed in an unattributed campaign since late August 2026, where socially engineered rogue clients executed a four-stage VBScript loader and backdoored clients pushed the same chain to every newly connected Host, producing worm-like spread. Payloads included a hidden ScreenConnect backdoor, UAC and Defender bypasses, a vulnerable WinRing0 driver, tunnelling and an XMRig miner, giving attackers persistent code execution on technician hosts and a pivot into downstream client networks.
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | ConnectWise ScreenConnect | No | No | Yes |
Vulnerability Details
Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-84869 | ConnectWise ScreenConnect client version before 26.6.5 | cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:* | CWE-269, CWE-862 |
Recommendations
Version 26.6.5 contains the vendor fix and is the only complete remediation. On-premises servers must be running version 25.4 or later before moving to 26.6.5. Cloud instances receive the update automatically, but administrators must still refresh or remove and redeploy host clients and agents after the upgrade.
Review ScreenConnect server audit logs for RunFiles or RanFiles entries executed from Process: Guest referencing 1.vbs through 4.vbs or WindowsServiceHost.vbs. Inspect endpoints for ScreenConnect.WindowsClient.exe spawning wscript.exe, the WindowsServiceHost Run key, and the malicious ScreenConnect instance ID 7a4d7d66502d4260. Hosts showing this activity should be reimaged from known-good media.
Remove or disable the TransferFiles permission (TransferFilesInSession in legacy versions) from all roles to block in-session file transfer and remote execute features — the vendor’s interim guidance from September 3. Enforce session policies requiring explicit Host confirmation and constrain child processes spawned by ScreenConnect client binaries.
Because the flaw is exploited through sessions the system already trusts, reset administrator and privileged user passwords, enforce multi-factor authentication on all ScreenConnect accounts, and validate every user and agent account against an approved inventory.
Restrict web interface and relay access to trusted IP ranges, place ScreenConnect behind a VPN or on internal networks where possible, segregate instances from sensitive network segments, enforce SSL/TLS, and apply least privilege to all roles.
Potential MITRE ATT&CK TTPs
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| SHA256 | 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020,de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457,19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260,110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66,de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede,ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de |
| IPv4 | 45[.]13[.]237[.]190, 146[.]59[.]55[.]107, 45[.]32[.]192[.]150, 15[.]204[.]185[.]204 |
| IPv4:Port | 131[.]123[.]40[.]98[:]8041 |
| Domains | tele-sync[.]opik[.]net, borertors92[.]anondns[.]net, homehub[.]opik[.]net |
| Filename | 1.vbs, 2.vbs, 3.vbs, 4.vbs, WindowsServiceHost.vbs, WindowsServiceHost.bat, value.txt, map.txt, out.tmp, out.enc, user.enc, acc.enc, combo.enc, runner.ps1, PyTorchFix.ps1, Password.exe, sys_cache.zip, Themes.exe, SearchIndex.exe, svcdrv64.sys |
| File Path | %TEMP%\value.txt, %TEMP%\map.txt, %TEMP%\out.enc, %TEMP%\runner.ps1, %APPDATA%\Microsoft\Windows\Templates\Classic\sys_cache.zip, C:\Users\Public\Libraries\Default\Lib\Lib1 |
| Registry Key | HKCU\Software\Microsoft\Windows\CurrentVersion\Run → WindowsServiceHost |
| ScreenConnect Instance ID | 7a4d7d66502d4260 |
| Detection Name | Trojan:Script/Wacatac.H!ml |
Patch Links
References
- connectwise.com — ScreenConnect security bulletin
- arcticwolf.com — CVE-2026-84869
- huntress.com — Rogue ScreenConnect installations
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
