Fake Adobe Reader Download Drops ScreenConnect via Fileless Loader
ID: a2e4556d-ac78-5cfa-aed8-77570bb78c86
STIX ID: report--a2e4556d-ac78-5cfa-aed8-77570bb78c86
Feed Name: GBHackers
Zscaler ThreatLabz discovered a deceptive campaign in which victims were lured to a fraudulent Adobe download page that delivered an obfuscated VBScript loader which invoked PowerShell to compile and run a .NET assembly entirely in memory, used COM-based auto-elevation to bypass UAC, and ultimately downloaded and installed a renamed ScreenConnect MSI to provide attackers remote access; the report includes technical details of the multi-stage, fileless execution chain and a set of IOCs (file hashes, Google Drive and direct MSI URLs) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
