logo

In-Memory Loader Drops ScreenConnect

ID: 2a6b30c1-0182-5174-897d-02b3b05d905b

STIX ID: report--2a6b30c1-0182-5174-897d-02b3b05d905b

Feed Name: Security Boulevard

Threat Score
72/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Kaivalya Khursale (Zscaler)

...
...

Zscaler ThreatLabz documents a multi-stage attack where a fraudulent Adobe download drops an obfuscated VBScript that launches PowerShell to compile and run an in‑memory .NET loader, enabling installation of ConnectWise ScreenConnect. The attackers used heavy obfuscation, reflection-based in-memory execution, PEB process masquerading, and an auto-elevated COM-based UAC bypass to evade detection; the report includes IOCs and Zscaler detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.