logo

In-Memory Loader Drops ScreenConnect

ID: 42b23a9d-c34d-5dc0-b895-0c1c471cc4e6

STIX ID: report--42b23a9d-c34d-5dc0-b895-0c1c471cc4e6

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-05-01

...
...

ThreatLabz describes a multi-stage, fileless ScreenConnect deployment that begins with an Adobe-themed lure delivering an obfuscated VBScript loader; the loader executes PowerShell to fetch an embedded .NET assembly, compiles and runs it in memory, uses PEB manipulation for process masquerading and abuses auto-elevated COM objects for silent privilege escalation, then downloads and installs ScreenConnect—resulting in remote-access capability on compromised hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.