As cited
Copy frozen at (site build).
threat intel
In-Memory Loader Drops ScreenConnect
In February 2026, Zscaler ThreatLabz identified a multi-stage attack chain that uses a fake Adobe Acrobat Reader download to distribute ConnectWise ScreenConnect, a legitimate remote access tool. The attack leverages obfuscated VBScript and PowerShell loaders, in-memory .NET compilation, process masquerading via Process Environment Block (PEB) manipulation, and User Account Control (UAC) bypass through auto-elevated Component Object Model (COM) objects to avoid detection and execute with elevated privileges. Once established, the final stage downloads and installs ScreenConnect on the victim's system using Windows Installer.
Why it matters: Defenders and endpoint detection and response (EDR) operators must monitor for obfuscated VBScript loaders, in-memory .NET execution via PowerShell Add-Type, PEB manipulation to detect process masquerading, and suspicious ScreenConnect installations, as this attack chain bypasses signature-based defenses and forensic recovery by keeping payloads entirely in memory.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
In-Memory Loader Drops ScreenConnect
In February 2026, Zscaler ThreatLabz identified a multi-stage attack chain that uses a fake Adobe Acrobat Reader download to distribute ConnectWise ScreenConnect, a legitimate remote access tool. The attack leverages obfuscated VBScript and PowerShell loaders, in-memory .NET compilation, process masquerading via Process Environment Block (PEB) manipulation, and User Account Control (UAC) bypass through auto-elevated Component Object Model (COM) objects to avoid detection and execute with elevated privileges. Once established, the final stage downloads and installs ScreenConnect on the victim's system using Windows Installer.
Why it matters: Defenders and endpoint detection and response (EDR) operators must monitor for obfuscated VBScript loaders, in-memory .NET execution via PowerShell Add-Type, PEB manipulation to detect process masquerading, and suspicious ScreenConnect installations, as this attack chain bypasses signature-based defenses and forensic recovery by keeping payloads entirely in memory.
- Source published
- First seen by Cybersecurity Tracker