New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
ID: a7d3a4a4-1a33-5483-9f95-efcbe7c310f7
STIX ID: report--a7d3a4a4-1a33-5483-9f95-efcbe7c310f7
Feed Name: securityonline.info
Security researchers (Zscaler ThreatLabz) uncovered a stealthy campaign that delivers a malicious loader disguised as an Adobe Acrobat Reader installer which uses heavily obfuscated VBScript and in-memory .NET reflection to deploy the legitimate remote-access tool ConnectWise ScreenConnect for unauthorized control; the chain includes UAC bypass via auto-elevated COM abuse and PEB manipulation to evade EDRs, and defenders are advised to monitor VBScript activity and audit remote access tool usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
