216.73.217.22

In-Memory Loader Drops ScreenConnect

· Published 10/04/2026 10:15 · Modified 10/04/2026 10:07

Export JSON

Essential information

Published
10/04/2026 10:15
Modified
10/04/2026 10:07
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
com abuse in-memory execution peb manipulation powershell staging remote access tool screenconnect uac bypass vbscript loader
Tags
2026-04-10 com abuse in-memory execution peb manipulation powershell staging remote access tool screenconnect uac bypass vbscript loader
Related entities
4 indicators, 4 observables, 16 techniques (mitre), 1 malware, 1 others

Description

In February 2026, an attack chain was discovered that utilized a fraudulent Adobe Acrobat Reader download page to deceive victims into installing ConnectWise's , a legitimate exploited for malicious purposes. The attack employs sophisticated evasion techniques including heavy obfuscation, .NET reflection for in-memory payload execution, and dynamic code construction. A initiates the chain by downloading and executing obfuscated PowerShell commands that compile C# code entirely in memory. The loader manipulates the Process Environment Block to masquerade as legitimate Windows processes and abuses auto-elevated COM objects to bypass User Account Control without user prompts. This multi-layered approach successfully evades signature-based defenses and hinders forensic analysis while ultimately deploying for unauthorized remote access.

External references