In-Memory Loader Drops ScreenConnect
ID: 42b23a9d-c34d-5dc0-b895-0c1c471cc4e6
STIX ID: report--42b23a9d-c34d-5dc0-b895-0c1c471cc4e6
Feed Name: Zscaler Security Research Blog
Threat Score
ThreatLabz describes a multi-stage, fileless ScreenConnect deployment that begins with an Adobe-themed lure delivering an obfuscated VBScript loader; the loader executes PowerShell to fetch an embedded .NET assembly, compiles and runs it in memory, uses PEB manipulation for process masquerading and abuses auto-elevated COM objects for silent privilege escalation, then downloads and installs ScreenConnect—resulting in remote-access capability on compromised hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
