Back to Intelligence

Rogue ScreenConnect Worm-Like Propagation (XMRig) + SockTz AI-Enabled LATAM Campaign: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 3, 2026
10 min read

Threat Summary

Two active intrusion campaigns surfaced in today's OTX pulse feed, and while they differ in tooling and geography, they share a common operational signature: abuse of legitimate tooling to blend into enterprise noise.

Campaign 1 — Rogue ScreenConnect + XMRig (global, opportunistic): Multiple organizations report intrusions beginning with social engineering that results in unauthorized installation of ConnectWise ScreenConnect — a legitimate remote monitoring and management (RMM) tool. Once installed, the rogue client executes a chain of four sequential VBScript payloads (1.vbs through 4.vbs) that profile the host, enumerate installed security products, establish persistence, and stage additional tooling. Critically, the modified ScreenConnect client exhibits worm-like propagation behavior, spreading laterally across unrelated hosts without additional social engineering — meaning a single phished user can seed an environment-wide outbreak. The final-stage payload is XMRig, the ubiquitous Monero cryptocurrency miner, indicating a financially motivated actor monetizing compromised compute at scale.

Campaign 2 — SockTz + AI-Augmented Intrusions (CL-CRI-1131, Latin America): Unit 42-tracked activity targeting transportation organizations and government entities in Mexico and Ecuador, plus financial-sector victims in Brazil. Operators leverage living-off-the-land (LotL) techniques, a self-hosted NextChat instance (an open-source ChatGPT UI) to operationally integrate AI tooling into the intrusion lifecycle — likely for phishing content generation, scripting assistance, and victim reconnaissance — and deploy SockTz, a SOCKS5 proxy implant that converts compromised hosts into relay nodes for anonymized C2 and follow-on access. The C2 infrastructure leans heavily on free dynamic DNS (duckdns.org) subdomains themed to Mexican government services (repuve, vacunas, intel, geo, apodo), strongly suggesting Spanish-language phishing lures impersonating federal programs.

Collective read: Both campaigns exemplify the modern crimeware playbook — trusted binaries (ScreenConnect), free dynamic DNS, AI-assisted operations, and proxy-based C2 — engineered to defeat reputation-based detection. Objective set: resource hijacking (XMRig) and persistent proxy footholds for resale or downstream intrusion (SockTz).

Threat Actor / Malware Profile

Rogue ScreenConnect / XMRig Loader Chain

  • Distribution: Social engineering (phishing/callback-style lures) prompting victims to install a trojanized or attacker-registered ScreenConnect client.
  • Payload behavior: Four-stage VBScript execution (1.vbs → 4.vbs via wscript.exe/cscript.exe): Stage 1 profiles the system (OS, domain, hardware), Stage 2 enumerates AV/EDR products (WMI root\SecurityCenter2 queries), Stage 3 installs persistence, Stage 4 downloads and executes XMRig and auxiliary tools.
  • C2 communication: ScreenConnect relay traffic plus direct miner callbacks; observed infrastructure includes http://homehub.opik.net:443 and dynamic-DNS host borertors92.anondns.net. XMRig speaks Stratum mining protocol to pool endpoints.
  • Persistence: ScreenConnect installs as a Windows service (ScreenConnect Client (*) service naming), supplemented by script-based persistence (Run keys/scheduled tasks typical of this chain).
  • Anti-analysis: Security-product enumeration before payload deployment; legitimate signed RMM binary defeats hash-based blocklisting; worm-like spread via the RMM's own remote-execution capability leaves minimal malware on disk.

SockTz (CL-CRI-1131)

  • Distribution: Phishing campaigns using Mexico/Ecuador government-themed lures (vehicle registry REPUVE, vaccination programs, intelligence/geospatial themes) aimed at transportation, government, and finance sectors.
  • Payload behavior: SockTz establishes a SOCKS5 proxy on the victim host, tunneling attacker traffic through the compromised machine — converting the endpoint into both a persistence point and an anonymity layer for further operations.
  • C2 communication: Dynamic DNS hostnames under *.duckdns.org (m-doxa-repuve, m-doxa-vacunas, m-doxa-intel, m-doxa-geo, m-doxa-apodo) resolving to rotating infrastructure; proxy traffic masquerades as ordinary outbound TLS.
  • Persistence: Service installation and LotL mechanisms (scheduled tasks, WMI) consistent with the campaign's LotL-heavy tradecraft.
  • Anti-analysis: Living-off-the-land execution chains, self-hosted NextChat AI tooling for operational support (reducing attributable infrastructure), and DDNS churn to evade static blocklists.

IOC Analysis

The indicator set decomposes into three operational buckets:

  1. FileHash-SHA256 (11 total): Hash indicators for the VBScript loader stages, modified ScreenConnect binaries, XMRig payloads, and SockTz implants. These are highest-fidelity for retro-hunting in EDR telemetry and email/web gateway logs, but expect short shelf life — VBScript stages are trivially re-obfuscated. Operationalize by pushing to EDR blocklists and querying historical process/file events, not just forward-blocking.
  2. Dynamic DNS hostnames (5): *.duckdns.org (SockTz) and *.anondns.net (ScreenConnect chain). DDNS domains rotate IPs frequently — block at the DNS resolver/sinkhole layer, not just the firewall, and alert on any resolution of the parent patterns (duckdns.org subdomains matching m-doxa-*, any anondns.net resolution in environments with no legitimate use).
  3. URL (1): http://homehub.opik.net:443 — C2/payload staging over non-standard port-to-scheme pairing (HTTP on 443), a detection opportunity in itself. Proxy and NGFW logs should flag protocol/port mismatches.

Tooling: Normalize indicators into STIX/TAXII for SIEM ingestion (MISP, OpenCTI); use shodan/censys for live resolution of DDNS hosts to catch IP drift; validate hashes against VirusTotal/MalwareBazaar before blocking to avoid false positives on legitimate ScreenConnect builds.

Detection Engineering

YAML
---
title: Rogue ScreenConnect Installation or Worm-Like RMM Execution
id: 9f2a1c3e-7b4d-4e5a-a1f2-sc01nn3ct001
status: experimental
description: Detects installation or execution of ScreenConnect RMM clients from non-standard paths or with suspicious naming, consistent with rogue ScreenConnect intrusions delivering XMRig via VBScript staging.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|contains: 'ScreenConnect'
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
      - '\ProgramData\'
  selection_child:
    ParentImage|contains:
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
  condition: selection_img and (selection_path or selection_child)
falsepositives:
  - Legitimate managed ScreenConnect deployments (whitelist known IT paths)
level: high
tags:
  - attack.execution
  - attack.command_and_control
  - attack.t1219
  - attack.t1059.005
date: 2026/10/03
---
title: VBScript Security Product Enumeration and Staging Chain
id: 8e1b2d4f-6c3a-4d2b-b9e1-vb5cr1pt0002
status: experimental
description: Detects sequential VBScript execution patterns (numbered .vbs payloads) and WMI-based AV enumeration consistent with the 1.vbs-4.vbs staging chain observed in rogue ScreenConnect/XMRig intrusions.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_proc:
    Image|endswith:
      - '\wscript.exe'
      - '\cscript.exe'
  selection_scriptname:
    CommandLine|contains:
      - '1.vbs'
      - '2.vbs'
      - '3.vbs'
      - '4.vbs'
  selection_avenum:
    CommandLine|contains:
      - 'AntiVirusProduct'
      - 'root\\SecurityCenter2'
      - 'Win32_ComputerSystem'
  condition: selection_proc and 1 of selection_*
falsepositives:
  - Legitimate administrative VBScript (rare in modern environments)
level: high
tags:
  - attack.execution
  - attack.discovery
  - attack.t1059.005
  - attack.t1518.001
date: 2026/10/03
---
title: SockTz C2 Dynamic DNS Resolution or XMRig Mining Callback
id: 7d0c3e5a-5f2b-4c1a-c8d2-s0cktz000003
status: experimental
description: Detects DNS resolution or network connections to known SockTz C2 duckdns subdomains, anondns.net ScreenConnect C2, and the opik.net staging URL observed in current OTX pulses.
author: Security Arsenal Threat Intelligence
logsource:
  category: dns
  product: windows
detection:
  selection:
    QueryName|contains:
      - 'm-doxa-apodo.duckdns.org'
      - 'm-doxa-geo.duckdns.org'
      - 'm-doxa-intel.duckdns.org'
      - 'm-doxa-vacunas.duckdns.org'
      - 'm-doxa-repuve.duckdns.org'
      - 'borertors92.anondns.net'
      - 'homehub.opik.net'
  condition: selection
falsepositives:
  - None expected; all listed hosts are confirmed malicious infrastructure
level: critical
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1568.002
  - attack.t1090
date: 2026/10/03
KQL — Microsoft Sentinel / Defender
// Security Arsenal — Rogue ScreenConnect / XMRig + SockTz Hunt (Sentinel)
// Part 1: Network indicators from OTX pulses
let maliciousHosts = dynamic(["m-doxa-apodo.duckdns.org","m-doxa-geo.duckdns.org","m-doxa-intel.duckdns.org","m-doxa-vacunas.duckdns.org","m-doxa-repuve.duckdns.org","borertors92.anondns.net","homehub.opik.net"]);
let netHits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (maliciousHosts)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
| extend Hunt = "IOC-Network";
// Part 2: VBScript staging + ScreenConnect execution behavior
let procHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where (FileName in~ ("wscript.exe","cscript.exe") and ProcessCommandLine has_any ("1.vbs","2.vbs","3.vbs","4.vbs","AntiVirusProduct","SecurityCenter2"))
   or (FileName has "ScreenConnect" and (FolderPath has_any ("\\Temp\\","\\Public\\","\\Roaming\\","\\ProgramData\\")))
   or (InitiatingProcessFileName has "ScreenConnect" and FileName in~ ("powershell.exe","cmd.exe","wscript.exe","cscript.exe","bitsadmin.exe","certutil.exe"))
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, FolderPath, InitiatingProcessFileName, SHA256
| extend Hunt = "Behavior-Execution";
// Part 3: File hash retro-hunt for OTX SHA256 indicators
let iocHashes = dynamic(["08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020","110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66","19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260","de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457","de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede","ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de","7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c"]);
let hashHits = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where SHA256 has_any (iocHashes)
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, ProcessCommandLine
| extend Hunt = "IOC-Hash";
union netHits, procHits, hashHits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — Rogue ScreenConnect / XMRig / SockTz Host Hunt
# Run elevated on suspect endpoints or deploy fleet-wide via GPO/Intune/EDR
$Report = @()

# 1. Rogue ScreenConnect services (legit installs have known, documented names)
$scServices = Get-CimInstance Win32_Service | Where-Object { $_.Name -match 'ScreenConnect' -or $_.DisplayName -match 'ScreenConnect' }
foreach ($s in $scServices) {
    $suspicious = $s.PathName -match 'Temp|Public|Roaming|ProgramData(?!\\ScreenConnect)'
    $Report += [PSCustomObject]@{Check='ScreenConnect Service'; Finding="$($s.Name) | $($s.PathName) | State=$($s.State)"; Suspicious=$suspicious}
}

# 2. Numbered VBScript staging files in common drop locations
$vbsPaths = @("$env:TEMP","$env:PUBLIC","$env:APPDATA","$env:LOCALAPPDATA","C:\ProgramData")
foreach ($p in $vbsPaths) {
    Get-ChildItem -Path $p -Recurse -ErrorAction SilentlyContinue -Include '1.vbs','2.vbs','3.vbs','4.vbs' |
        ForEach-Object { $Report += [PSCustomObject]@{Check='VBScript Stager'; Finding=$_.FullName; Suspicious=$true} }
}

# 3. Run-key persistence referencing scripts or RMM tooling
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
    if (Test-Path $k) {
        (Get-ItemProperty $k).PSObject.Properties | Where-Object { $_.Value -match 'vbs|ScreenConnect|xmrig|duckdns|anondns' } |
            ForEach-Object { $Report += [PSCustomObject]@{Check='Run Key Persistence'; Finding="$k :: $($_.Name) = $($_.Value)"; Suspicious=$true} }
    }
}

# 4. Scheduled tasks launching scripts/miners
Get-ScheduledTask | Where-Object { ($_.Actions.Execute -match 'wscript|cscript|powershell') -and ($_.Actions.Arguments -match 'vbs|xmrig|duckdns|anondns|http') } |
    ForEach-Object { $Report += [PSCustomObject]@{Check='Scheduled Task'; Finding="$($_.TaskName) -> $($_.Actions.Execute) $($_.Actions.Arguments)"; Suspicious=$true} }

# 5. Active connections to known C2 infrastructure
$c2Patterns = 'duckdns\.org|anondns\.net|opik\.net'
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | ForEach-Object {
    try {
        $dns = (Resolve-DnsName $_.RemoteAddress -ErrorAction Stop).NameHost
        if ($dns -match $c2Patterns) {
            $Report += [PSCustomObject]@{Check='C2 Connection'; Finding="PID $($_.OwningProcess) -> $($_.RemoteAddress):$($_.RemotePort) [$dns]"; Suspicious=$true}
        }
    } catch {}
}

# 6. XMRig artifacts (miner binary, config, high-CPU unknown processes)
Get-ChildItem -Path 'C:\' -Recurse -Depth 4 -ErrorAction SilentlyContinue -Include 'xmrig*.exe','config.json' |
    Where-Object { $_.FullName -match 'xmrig' } |
    ForEach-Object { $Report += [PSCustomObject]@{Check='XMRig Artifact'; Finding=$_.FullName; Suspicious=$true} }

$Report | Where-Object { $_.Suspicious } | Format-Table -AutoSize
if (-not ($Report | Where-Object { $_.Suspicious })) { Write-Host '[+] No indicators of compromise found.' -ForegroundColor Green }

Response Priorities

Immediate (0–4 hours):

  • Block all five m-doxa-*.duckdns.org hostnames, borertors92.anondns.net, and homehub.opik.net at DNS resolver, proxy, and EDR network layers; push the 11 SHA256 hashes to EDR blocklists and email/web gateway retro-search.
  • Inventory every ScreenConnect (and other RMM — AnyDesk, TeamViewer, Splashtop) installation in the environment; treat any instance outside IT's managed deployment as an incident. The worm-like propagation means one rogue client likely implies multiple compromised hosts.
  • Isolate any host with confirmed C2 resolution or IOC hash execution; capture memory before remediation to recover miner configuration and staged payloads.

24 hours:

  • While neither campaign is primarily credential-theft focused, SockTz proxy access and RMM footholds enable interactive intrusion — force credential resets for any user on a confirmed-compromised host, and audit for newly created local/domain accounts and unauthorized admin group additions.
  • Review authentication logs for anomalous remote sessions correlating with ScreenConnect install timestamps; hunt for lateral movement (SMB/WinRM/RDP) originating from infected hosts during the dwell window.
  • For LATAM-region business units: escalate phishing-awareness alerting on government-themed lures (REPUVE, vaccination, geospatial programs) in Spanish-language email flows.

1 week:

  • Implement an RMM allowlist policy: block execution of unapproved remote access tools via application control (WDAC/AppLocker) — this single control breaks the ScreenConnect campaign's core mechanism.
  • Deploy DNS-layer categorization blocking or alerting on free dynamic-DNS TLDs (duckdns.org, anondns.net, no-ip.*) absent documented business need.
  • Constrain VBScript: disable wscript/cscript via attack surface reduction rules for users without a business justification, and enable AMSI script content logging.
  • Add egress controls for Stratum mining protocol and non-browser traffic on port 443 failing TLS inspection, closing both the XMRig monetization path and SockTz-style proxy tunnels.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.