logo

Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage

ID: 96b3c3c1-56e2-5b97-b716-965e0433ed38

STIX ID: report--96b3c3c1-56e2-5b97-b716-965e0433ed38

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

CYFIRMA discovered a sophisticated intrusion campaign delivering a weaponized PowerShell loader disguised as sysupdate.jpeg that bypasses AMSI, dynamically compiles a unique launcher (uds.exe) with csc.exe, performs a fileless UAC escalation, and installs a trojanized ConnectWise ScreenConnect (named OneDriveServers) that provides persistent remote access, credential harvesting, hidden desktop capabilities, and strong session-specific encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.