In-Memory Loader Drops ScreenConnect
ID: 2a6b30c1-0182-5174-897d-02b3b05d905b
STIX ID: report--2a6b30c1-0182-5174-897d-02b3b05d905b
Feed Name: Security Boulevard
Threat Score
Zscaler ThreatLabz documents a multi-stage attack where a fraudulent Adobe download drops an obfuscated VBScript that launches PowerShell to compile and run an in‑memory .NET loader, enabling installation of ConnectWise ScreenConnect. The attackers used heavy obfuscation, reflection-based in-memory execution, PEB process masquerading, and an auto-elevated COM-based UAC bypass to evade detection; the report includes IOCs and Zscaler detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
