logo

SilentConnect Uses Fake Invites to Deploy ScreenConnect RAT

ID: fb2fe960-0065-532c-9cb8-2a1f737abcdb

STIX ID: report--fb2fe960-0065-532c-9cb8-2a1f737abcdb

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SILENTCONNECT is a multi-stage Windows loader distributed via phishing lures that abuse Cloudflare/Google Drive hosting and fake invitation pages; a VBScript downloads and launches a PowerShell chain that compiles a .NET loader in-memory, uses curl.exe to fetch additional code, allocates RWX memory, performs PEB masquerading and a CMSTPLUA UAC bypass, and modifies Defender exclusions before silently installing a ScreenConnect MSI to grant persistent remote access via an attacker-controlled ScreenConnect server. The campaign leverages living-off-the-land binaries (curl, msiexec), trusted hosting to avoid simple network blocks, and reuse of infrastructure patterns (download_invitee.php) that allowed researcher pivots; defenders are advised to monitor for VBScript downloads, Add-Type PowerShell usage with remote fetches, unexpected Defender exclusion changes, unauthorized RMM installations, and outbound ScreenConnect connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.