logo

From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

ID: f0b742a2-819b-59fe-ae18-bf14a62d3b57

STIX ID: report--f0b742a2-819b-59fe-ae18-bf14a62d3b57

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-27

...
...

Elastic Security Labs describes an active campaign delivering a newly observed .NET loader named SILENTCONNECT via phishing lures that use Cloudflare Turnstile and Google Drive hosting. The chain uses minimally obfuscated VBScript to run PowerShell that compiles and executes C# in memory; the loader performs PEB masquerading, NT API usage, UAC bypass and adds a Defender exclusion before silently installing a ScreenConnect RMM client that provides hands-on access to victim machines. The report includes YARA detection rules and multiple SHA-256 hashes, domains, and an IP address as observables.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.