{"id":11483,"date":"2026-03-20T10:03:41","date_gmt":"2026-03-20T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/silentconnect-uses-vbscript-powershell-and-peb-masquerading-to-deploy-screenconnect\/"},"modified":"2026-03-20T10:03:41","modified_gmt":"2026-03-20T10:03:41","slug":"silentconnect-uses-vbscript-powershell-and-peb-masquerading-to-deploy-screenconnect","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/20\/silentconnect-uses-vbscript-powershell-and-peb-masquerading-to-deploy-screenconnect\/","title":{"rendered":"SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect"},"content":{"rendered":"<p>    SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. <\/p>\n<p>It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on victim systems. <\/p>\n<p>Once deployed, ScreenConnect gives the attacker full hands-on keyboard control over the compromised machine, posing a serious threat to corporate environments worldwide.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The infection begins when a target receives a phishing email with a link appearing to lead to a legitimate invitation or proposal. Clicking it redirects the victim to a <a href=\"https:\/\/cybersecuritynews.com\/sectoprat-as-weaponized-cloudflare\/\" id=\"97378\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare Turnstile<\/a> CAPTCHA page asking them to verify they are human. <\/p>\n<p>Once the checkbox is clicked, a VBScript file named E-INVITE.vbs automatically downloads to the machine. <\/p>\n<p>Threat actors have used convincing filenames such as Proposal-03-2026.vbs to make lures appear credible and lower the victim\u2019s guard before execution.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBsvUIu-w34V8w3ny6rvgcgZBqu67yGj-aFJhesnrDyrCUGMMSonSniLSbCE90-qCxpsw1xRionb2AlBWF3a12AaMDa_yYeVoJQvh336PP-Nb7D0N7ww8IeP7qJsfpqyjHz8ZAWGJmp9IQZg1Rm8RiTCxH9t47Pa71FR2y4YIgze3s5NRDhnBH9GBAMJE\/s16000\/Cloudflare%2520CAPTCHA%2520page%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Cloudflare CAPTCHA page (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Cloudflare CAPTCHA page (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p><a href=\"https:\/\/www.elastic.co\/security-labs\/silentconnect-delivers-screenconnect\" id=\"https:\/\/www.elastic.co\/security-labs\/silentconnect-delivers-screenconnect\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Elastic Security Labs researchers identified the campaign<\/a> in early March 2026 after a living-off-the-land style infection generated multiple behavioral alerts in a short period. <\/p>\n<p>The initial VBScript download triggered a Suspicious <a href=\"https:\/\/cybersecuritynews.com\/windows-rrasman-0-day-vulnerability\/\" id=\"142314\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Script<\/a> Downloaded from the Internet detection rule, giving analysts a pivot point to trace the infection using file origin URL fields. <\/p>\n<p>The VBScript was hosted on Cloudflare\u2019s r2.dev storage while the C# payload was fetched from Google Drive \u2014 two trusted platforms that most network defenses are unlikely to block.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>SILENTCONNECT blends into normal Windows activity to stay under the radar. The VBScript uses a children\u2019s story as a decoy while hiding real instructions inside Replace and Chr functions. <\/p>\n<p>When decoded, it fires a PowerShell command that uses the built-in curl.exe to download a C# source file, compiles it at runtime through Add-Type, and runs it entirely in memory. <\/p>\n<p>Since no malicious executable is written to disk, most endpoint <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a> struggle to detect this behavior in real time.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJwLGpyOTHKFkecTTJ56bM0UnPqXnthmlrId_cHZ452KauU8GCEAJzPsBCC1Bhyphenhyphen5JK2Atza1W3SM1znGWiaaoQfqy-1wokheVXWOMJLI_V9IpK8_0psAWBz75zomxw-JtrL_8CJasx7SEhogkQ-KxZn9q2XSCDd9fb0FeiI2CihbokFxXoSQWcKAnYB50\/s16000\/Obfuscated%2520VBScript%2520using%2520Chr%28%29%2520and%2520Replace%28%29%2520functions%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Obfuscated VBScript using Chr() and Replace() functions (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Obfuscated VBScript using Chr() and Replace() functions (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>The threat actor\u2019s infrastructure also reveals a consistent pattern. A <a href=\"https:\/\/cybersecuritynews.com\/hr-it-related-phishing-emails-are-top-clicked\/\" id=\"85221\" target=\"_blank\" rel=\"noreferrer noopener\">phishing email<\/a> on VirusTotal with the subject YOU ARE INVITED was traced to dan@checkfirst[.]net[.]au, impersonating a project proposal from a fake company. <\/p>\n<p>The attacker reused the same URI path \u2014 download_invitee.php \u2014 across multiple compromised websites, which proved to be an OPSEC mistake, allowing researchers to map out the full campaign infrastructure through targeted VirusTotal searches.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"peb-masquerading-and-defense-evasion\"><strong>PEB Masquerading and Defense Evasion<\/strong><\/h2>\n<p>Once the .NET loader runs, SILENTCONNECT moves quickly to disappear from security tool view. After sleeping for 15 seconds, it allocates executable memory through NtAllocateVirtualMemory and copies a small shellcode stub into that region.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiupu1XUYBiNw91vb4bqUjo5zDRK-Gol0NWeMGWggsSgwkM4Q65Sk7gZDCzg2ti1DLHO9iEKTjuLZnCGmTQx2IFmlzmZS9HyPzQtGkv1nQ7FsfavWqpyUx3kBgDIL_E174sMcF8G0niN8ChLkVJAUIfI91pBjesuajyuhSr2vH5hkDB4sR2_B6nko2_Ry4\/s16000\/Copying%2520shellcode%2520into%2520memory%2520via%2520NtAllocateVirtualMemory%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Copying shellcode into memory via NtAllocateVirtualMemory (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Copying shellcode into memory via NtAllocateVirtualMemory (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>This shellcode retrieves the address of the Process Environment Block, a Windows structure that tracks all modules loaded in a running process, letting the malware operate at a low system level while bypassing commonly monitored API calls.<\/p>\n<p>With the PEB address in hand, SILENTCONNECT performs PEB masquerading by locating its own module list entry and overwriting both the BaseDLLName and FullDllName fields to display winhlp32.exe and c:windowswinhlp32.exe. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjvqMMMKJM80NsGLa5Xdi84F3yzelAmBllte_h8G073iGzKvYboEdrtT3YWMMPaZRR5TKmiqIvZDiaDb1RRaga6FHBoCD0rvT-M03Nwa4c-2IDibSxV2AmSZYWXGFlOSpevPrgmpQ4A6wBt1siY_MjbDhhY4Jf-FsJa_CjbZ5b3ky7uNz6-rRHVDk2sWY0\/s16000\/PEB%2520masquerading%2520feature%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"PEB masquerading feature (Source - Elastic)\"><figcaption class=\"wp-element-caption\">PEB masquerading feature (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>Since many EDR solutions rely on PEB data as a trusted reference when identifying suspicious processes, this name swap disguises the loader as a harmless Windows help utility, making it nearly invisible to automated detection.<\/p>\n<p>Before installing ScreenConnect, the loader executes a UAC bypass through the CMSTPLUA COM interface, stores its parameters in reverse order as obfuscation, and silently adds a Microsoft Defender exclusion for exe files. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjrNh18KnnRdz1CPvA46doo4kb4RR5xYg6vzMSdytRWEP88z-uQIn3zWEeKSaNRIgF3LCKFGZv1TSto_4StpVJfisXZQ8MSw2jWTo1ht8gDbcEOgLfnC0QKsbXMpVh-00s3UczA75HQgLefOijAb066RrpCmdFTW4ppYtKhGeEC1FofyBReSnOeaa5bux8\/s16000\/SILENTCONNECT%2520adding%2520Microsoft%2520Defender%2520exception%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"SILENTCONNECT adding Microsoft Defender exception (Source - Elastic)\"><figcaption class=\"wp-element-caption\">SILENTCONNECT adding Microsoft Defender exception (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>It then downloads the ScreenConnect MSI from bumptobabeco[.]top via curl.exe, installs it through msiexec.exe, and sets it up as a Windows service beaconing to the attacker\u2019s server over TCP port 8041.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Organizations should routinely audit their environments for unauthorized RMM deployments and monitor outbound traffic to unknown ScreenConnect server addresses. <\/p>\n<p>Security teams should flag PowerShell commands combining Add-Type with remote downloads, alert on <a href=\"https:\/\/cybersecuritynews.com\/hackers-leverage-vbscript-files-to-deploy-masslogger\/\" id=\"111631\" target=\"_blank\" rel=\"noreferrer noopener\">VBScript files<\/a> fetched from the internet, and watch for unexpected Defender exclusion changes. <\/p>\n<p>Tracking NtAllocateVirtualMemory calls from .NET processes can also help catch this threat before it reaches full compromise.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/d681477e-25e9-4c22-bae6-fb30f74d1dea\/SILENTCONNECT-Uses-VBScript-PowerShell-and-PEB-Masquerading-to-Deploy-ScreenConnect.pdf?AWSAccessKeyId=ASIA2F3EMEYEV7ZX3KHS&amp;Signature=XjYHKW3aaizKW3zgjOJx6C5t8SE%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEGYaCXVzLWVhc3QtMSJHMEUCIQCUp7JiwZirsRQLexn6cS5SvGldJETgycmONqeKHKActAIgKk%2F0Pr5wkdgtAFCGpECTAjmE94JniYNt5lLtX6W2CZwq8wQILxABGgw2OTk3NTMzMDk3MDUiDKsrcm1AwXfSc677KSrQBGVswtpRXSLVwcraVkXFllm9LEzwrCDWI06B8EEPxE2S0xbNbXM7MAflXICO4a3Bqaxk0%2Fywou4fMJlxlcN%2B0j3KvJXBMyikaYvOwMMN2jcRdKRHp%2F%2BeSfVozGoOMWfRiUHEdz0%2Fjc3nQaxiujSOO6KKKxFEpy%2FxWGXCBsvg1Tjwfi3vIrnElvhEbLBItNhdMnN6dYwxHKWC8%2BkQhKVLReawJ4JN3Z6XfeYuRdUcjPW9XDHB9c8yb1P3dAGMZR7uR23MIO%2B1YtG6NbiUhMioJk4Mvlloa2d%2FHk1d0gzAY5ZCg8P%2FUkg%2BfhKIKt3pl2nVkteG1Cqz302zcR%2BTwAgGxY8b6phH3TGX%2FkCAY1X20HAHhoSzuuUFreSo2HAUB6GfUg0gNuoJ%2FXgtSlG%2FeF2O9BcGQbD%2FaFvij2dHTMvwUimRh%2B4gnDROsJjl8lnYqm4iP9A2xT3fpBstw0XAZhXJM3TCL9gAE1sf8Q13KtLf5B6U9N5TrE4VNSLxMYsrvBCRdLmxi4WnI%2FEAGOBUBd3wHziPbxP57uhhsBW%2B75Y90Eltr2m%2B5bPKkuHF0M1b4vxUWECpfdpT0MwOy2bqbk69noFkX4vh%2Bxiz00VENntlag%2FrUwshzchEj3VBrr6NaWlfoMXIEzVNbiaD4ctvTpgF5eL7%2BtbF48Xds4xaax23HnD%2BHaG93OihBmw47EgE0mrzvqqBiMw%2FziLa%2BfI2mt4SfBAHzNlPPfpBUVkGEolZY4uEgoUmPiECA7mFaZPX5XBOX1FYoGfqytpn15VvznibBGIw8L3zzQY6mAE%2Ftfc5C3KbvRXYKsCAu4WVFdqQJXRYBa4KT%2BzvuRY6WnlQnK4xsvplezigKMgowZco56RX3ct0Z2FXXrFBthOHp2yHtqRxIWK%2F3Yo77CmTYJqk01FCfhFSt1fa5qvtfnAsUvthyYCIh4OKMGf4TNDS%2BTVR%2Bn8InJNfwAHD44n49ujdlz9XGkqDtwzPlz0Kyk4CQd5oMwDogg%3D%3D&amp;Expires=1773987400\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/silentconnect-uses-vbscript-powershell\/\">SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/silentconnect-uses-vbscript-powershell\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on victim systems. Once deployed, ScreenConnect [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11483","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11483"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11483"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11483\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}