Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
ID: 96b3c3c1-56e2-5b97-b716-965e0433ed38
STIX ID: report--96b3c3c1-56e2-5b97-b716-965e0433ed38
Feed Name: securityonline.info
Threat Score
CYFIRMA discovered a sophisticated intrusion campaign delivering a weaponized PowerShell loader disguised as sysupdate.jpeg that bypasses AMSI, dynamically compiles a unique launcher (uds.exe) with csc.exe, performs a fileless UAC escalation, and installs a trojanized ConnectWise ScreenConnect (named OneDriveServers) that provides persistent remote access, credential harvesting, hidden desktop capabilities, and strong session-specific encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
