logo

The Rise of SILENTCONNECT: New Stealthy Loader Exploits Trusted Cloud Giants

ID: 461c9f16-5e08-5d97-a541-b5bafa0cb62d

STIX ID: report--461c9f16-5e08-5d97-a541-b5bafa0cb62d

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Elastic Security Labs discovered a live campaign using a new loader called SILENTCONNECT that delivers legitimate RMM tools (notably ConnectWise ScreenConnect) to victim machines via a Cloudflare Turnstile lure and Google Drive/Cloudflare hosting; the loader employs LOLBins, a VBScript-to-in-memory C# execution chain via PowerShell, UAC bypass, Windows Defender exclusions, and low-level API/PEB masquerading to maintain stealth and persistent hands-on-keyboard access, and the lab recommends auditing RMM usage and adopting behavioral monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.