Hackers Use Weaponized JPEG File to Deploy Trojanized ScreenConnect Malware
ID: 6d1a5711-6ac1-5ed4-85e3-387a043a566a
STIX ID: report--6d1a5711-6ac1-5ed4-85e3-387a043a566a
Feed Name: cybersecurityNews.com
Operation SilentCanvas is a sophisticated multi-stage Windows malware campaign that delivers a PowerShell loader disguised as a JPEG (sysupdate.jpeg) to fetch and deploy a trojanized ConnectWise ScreenConnect, achieve silent UAC bypass via registry manipulation and ComputerDefaults.exe auto-elevation, run additional payloads in memory, compile a unique launcher with csc.exe (uds.exe), and maintain persistence while capturing credentials and providing full remote access. The report includes technical details, recommended mitigations, and multiple IoCs (IPs, domains, hashes, filenames, and file paths) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
