Hackers are exploiting an extremely serious authentication bypass vulnerability to compromise unpatched ScreenConnect servers and deploy LockBit ransomware payloads to networks.

The vulnerability is tracked as CVE-2024-1709 and has been used in attacks since Tuesday, a day after ConnectWise released security updates . The company also patched a second serious vulnerability, CVE-2024-1708 , which can only be exploited by highly privileged threat actors.
Both vulnerabilities affect all versions of ScreenConnect. For this reason, the company has removed all license restrictions so that customers with expired licenses can upgrade to the latest software version.
According to the platform, Shadowserver, the CVE-2024-1709 vulnerability is now being used in multiple attacks, with 643 IPs currently targeting vulnerable servers.
See also: LockBit ransomware: Developers had created a new version before the authorities "hit" it
Shodan monitors over 8,659 ScreenConnect servers and only 980 are using the updated ScreenConnect version 23.9.8.
CISA CVE -2024-1709 to the List of Known Exploitable Vulnerabilities, ordering US to secure their servers by February 29.
LockBit ransomware: Infecting ScreenConnect servers via vulnerability
According to Sophos X-Ops, hackers deploying LockBit ransomware on victims' systemsusing exploits targeting these two ScreenConnect vulnerabilities.
Cybersecurity firm Huntress confirmed the findings, citing a specific attack by the LockBit ransomware exploiting CVE-2024-1709.
The above shows that despite the recent dismantling of the ransomware group's infrastructure by law enforcement authorities, there are still some affiliates using Lockbit ransomware in attacks.

“We can't attribute this directly to the larger LockBit group, but it's clear that lockbit has a large reach that extends to tools and various affiliate groups that have not been completely affected, even after being taken down by law enforcement“.
See also: LockBit ransomware: $10 million reward for information on its leaders
Operation Cronos: LockBit ransomware in the sights of the authorities
The LockBit ransomware infrastructure was seized this week after the group's dark web sites were taken down. Law enforcement agencies from multiple countries helped in this success.
As part of this joint operation, a tool decryption (LockBit 3.0 Black Ransomware) was created and offered free of charge to victims, while 200 crypto wallets were also seized.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Two members were arrested in Poland and Ukraine, while French and US authorities issued three international arrest warrants and five indictments targeting other threat . The US Department of Justice brought two of these indictments against Russian suspects Artur Sungatov and Ivan Gennadievich Kondratiev (aka Bassterlord).
Law enforcement also released additional information about the seized data leak website, revealing that LockBit had at least 188 affiliates.
The LockBit ransomware gang has been linked to several major attacks.
The US State Department is offering rewards of up to $15 million for information about ransomware gang members and their associates.
However, as evidenced by the exploitation of the vulnerability in ScreenConnect servers, LockBit ransomware continues to pose a threat. Already, since yesterday, it has been known that the group has been secretly working on a new version of the malware called LockBit-NG-Dev (which would likely become LockBit 4.0).
See also: LockBit ransomware: Member arrests and decryption tool

LockBit ransomware attacks can have serious consequences for networks. First, data loss, as the ransomware encrypts files , preventing access to them (unless the corresponding decryption key is available).
Additionally, these attacks can cause network disruption, as ransomware can block access to critical services and applications.
Financial losses are also serious , as attackers often demand a ransom to decrypt files. The costs can include both the immediate payment of the ransom and the costs associated with restoring the network.
Finally, LockBit ransomware attacks can undermine the trust of customers and partners if it becomes known that their data has been exposed or encrypted. This can lead to lost business opportunities and have long-term repercussions for the company's reputation.
Source: www.bleepingcomputer.com
