logo

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

ID: 45ff5031-4773-54e8-924f-568da1adf29a

STIX ID: report--45ff5031-4773-54e8-924f-568da1adf29a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

SILENTCONNECT is a sophisticated multi-stage malware loader observed since at least March that delivers a C# .NET loader via an obfuscated VBScript phishing lure; it compiles and executes payloads in-memory, uses PEB masquerading to spoof process names, performs a UAC bypass and adds Defender exclusions, then installs ConnectWise ScreenConnect to provide attackers full remote control. Researchers traced the campaign through reused URI paths and hosting on trusted services (Cloudflare R2, Google Drive), and recommend monitoring for VBScript downloads, PowerShell Add-Type remote-download patterns, NtAllocateVirtualMemory calls from .NET processes, unexpected Defender exclusions, and unauthorized RMM deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.