Malicious JPEG Campaign Delivers Trojanized ScreenConnect Payloads
ID: c824e0a2-f2c6-5946-b8d6-59915d0dd594
STIX ID: report--c824e0a2-f2c6-5946-b8d6-59915d0dd594
Feed Name: Cyber Press
CYFIRMA reports a sophisticated campaign that delivers a modified ConnectWise ScreenConnect remote-access tool via a deceptive image named sysupdate.jpeg distributed through phishing, fake updates, or malicious links. The attackers build malicious executables on the victim host using local compilation to evade signature-based detection, tamper signed components to disable security checks, and establish encrypted C2 (example: legitserver.theworkpc.com:8041) to perform continuous screen capture, audio recording, print interception, and credential harvesting; defenders are advised to monitor remote administration platforms and enforce strict application execution policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
