logo

Hackers Use Weaponized JPEG File to Deploy Trojanized ScreenConnect Malware

ID: 6d1a5711-6ac1-5ed4-85e3-387a043a566a

STIX ID: report--6d1a5711-6ac1-5ed4-85e3-387a043a566a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

Operation SilentCanvas is a sophisticated multi-stage Windows malware campaign that delivers a PowerShell loader disguised as a JPEG (sysupdate.jpeg) to fetch and deploy a trojanized ConnectWise ScreenConnect, achieve silent UAC bypass via registry manipulation and ComputerDefaults.exe auto-elevation, run additional payloads in memory, compile a unique launcher with csc.exe (uds.exe), and maintain persistence while capturing credentials and providing full remote access. The report includes technical details, recommended mitigations, and multiple IoCs (IPs, domains, hashes, filenames, and file paths) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.