In-Memory Loader Drops ScreenConnect
Essential information
- Published
- 10/04/2026 10:15
- Modified
- 10/04/2026 10:07
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- com abuse in-memory execution peb manipulation powershell staging remote access tool screenconnect uac bypass vbscript loader
- Tags
- 2026-04-10 com abuse in-memory execution peb manipulation powershell staging remote access tool screenconnect uac bypass vbscript loader
- Related entities
- 4 indicators, 4 observables, 16 techniques (mitre), 1 malware, 1 others
Description
In February 2026, an attack chain was discovered that utilized a fraudulent Adobe Acrobat Reader download page to deceive victims into installing ConnectWise's ScreenConnect, a legitimate remote access tool exploited for malicious purposes. The attack employs sophisticated evasion techniques including heavy obfuscation, .NET reflection for in-memory payload execution, and dynamic code construction. A VBScript loader initiates the chain by downloading and executing obfuscated PowerShell commands that compile C# code entirely in memory. The loader manipulates the Process Environment Block to masquerade as legitimate Windows processes and abuses auto-elevated COM objects to bypass User Account Control without user prompts. This multi-layered approach successfully evades signature-based defenses and hinders forensic analysis while ultimately deploying ScreenConnect for unauthorized remote access.