SilentConnect Uses Fake Invites to Deploy ScreenConnect RAT
ID: fb2fe960-0065-532c-9cb8-2a1f737abcdb
STIX ID: report--fb2fe960-0065-532c-9cb8-2a1f737abcdb
Feed Name: GBHackers
SILENTCONNECT is a multi-stage Windows loader distributed via phishing lures that abuse Cloudflare/Google Drive hosting and fake invitation pages; a VBScript downloads and launches a PowerShell chain that compiles a .NET loader in-memory, uses curl.exe to fetch additional code, allocates RWX memory, performs PEB masquerading and a CMSTPLUA UAC bypass, and modifies Defender exclusions before silently installing a ScreenConnect MSI to grant persistent remote access via an attacker-controlled ScreenConnect server. The campaign leverages living-off-the-land binaries (curl, msiexec), trusted hosting to avoid simple network blocks, and reuse of infrastructure patterns (download_invitee.php) that allowed researcher pivots; defenders are advised to monitor for VBScript downloads, Add-Type PowerShell usage with remote fetches, unexpected Defender exclusion changes, unauthorized RMM installations, and outbound ScreenConnect connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
