Threat reportMalwareTL-2026-0343

SILENTCONNECT: Fileless In-Memory .NET Loader Delivers ScreenConnect RAT via VBScript, PEB Masquerading, and UAC Bypass

highACTIVE

SILENTCONNECT (TL-2026-0343), also tracked as SILENTCONNECT, is a high-severity malware campaign, first published 2026-04-09. It has no confirmed attribution, affects Microsoft Windows, maps to 17 MITRE ATT&CK techniques (T1027, T1036, T1059), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-0343

Threat ID
TL-2026-0343
Also known as
SILENTCONNECT
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
enterprise, government, financial, healthcare, technology, education
Target regions
North America, Europe, Middle East, Asia Pacific
Detection rules
9
Indicators of compromise
28

Malware and tooling in SILENTCONNECT

Malware and tooling: SILENTCONNECT, ConnectWise Control, ConnectWise ScreenConnect, Syncro RMM

How SILENTCONNECT works

SILENTCONNECT is a multi-stage fileless loader campaign active since March 2025 that uses VBScript lures disguised as digital invitations to download C# source code from Google Drive, compile it in-memory via PowerShell Add-Type, perform PEB masquerading and CMSTPLUA COM UAC bypass, then silently deploy ConnectWise ScreenConnect RMM as a persistent backdoor with C2 over TCP port 8041.

SILENTCONNECT is a sophisticated multi-stage fileless malware loader campaign first observed in March 2025 and publicly disclosed by Elastic Security Labs in March 2026. The campaign targets Windows systems through social engineering, using phishing emails with fake digital invitations (party invitations, DocuSign documents, Microsoft Teams meeting links) to lure victims into executing malicious VBScript files.

The infection chain begins when a victim clicks a link in a phishing email, which redirects through a Cloudflare Turnstile CAPTCHA page — a technique used to evade automated analysis and add legitimacy. After completing the CAPTCHA, the victim downloads a VBScript file (commonly named E-INVITE.vbs or themed after legitimate documents like 'Alaska Airlines 2026 Fleet & Route Expansion Summary.vbs'). The VBScript files are minimally obfuscated, using a children's story as decoy text and employing Replace() and Chr() functions for de-obfuscation.

Upon execution, the VBScript spawns PowerShell with -ExecutionPolicy Bypass, which uses the built-in curl.exe (a living-off-the-land binary) to download a C# source file named FileR.txt from Google Drive. This C# payload is then compiled and executed entirely in-memory using the PowerShell Add-Type cmdlet, leaving no malicious executable on disk — a key evasion technique that defeats most traditional endpoint security tools.

The compiled SILENTCONNECT loader incorporates several advanced evasion techniques. It implements a 15-second sleep delay before payload execution to evade sandbox analysis. It performs PEB (Process Environment Block) masquerading by locating its own module list entry and overwriting both the BaseDLLName and FullDllName fields to display winhlp32.exe and c:\windows\winhlp32.exe respectively, making the malicious process appear as a legitimate Windows binary to security tools that inspect PEB data. The loader uses direct NTAPI calls through ntdll.dll and ole32.dll rather than higher-level Windows APIs, further evading API-level monitoring. The C# payload employs constant unfolding to conceal byte arrays and stores launch parameters in reverse character array order as additional obfuscation.

For privilege escalation, SILENTCONNECT performs a UAC bypass through the CMSTPLUA COM interface, using the LaunchElevatedCOMObjectUnsafe function. The elevation moniker string is stored reversed as ':wen!rotartsinimdA:noitavelE' to evade static detection. Once elevated, the loader adds a Windows Defender exclusion for .exe files via WMI, effectively neutering real-time protection for all executable files.

The final payload is a ConnectWise ScreenConnect (formerly ConnectWise Control) MSI installer, downloaded from the attacker-controlled domain bumptobabeco.top and silently installed via msiexec. ScreenConnect persists as a Windows service and establishes command-and-control communication over TCP port 8041 to bumptobabeco.top, with relay infrastructure at instance-lh1907-relay.screenconnect.com. An alternative exploitation path using Syncro RMM (ViewDocs.exe) has also been identified.

The threat actor demonstrates poor operational security, reusing the URI path download_invitee.php across multiple compromised websites (including imansport.ir and solpru.com). Infrastructure abuses trusted providers including Cloudflare for CAPTCHA delivery and Google Drive for payload hosting. The phishing sender domain checkfirst.net.au with sender dan@checkfirst.net.au has been identified across multiple lures.

MITRE ATT&CK techniques used in TL-2026-0343

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

persistence

T1543 Create or Modify System Process

privilege-escalation

T1548 Abuse Elevation Control Mechanism

initial-access

T1566 Phishing

resource-development

T1584 Compromise Infrastructure; T1608 Stage Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in SILENTCONNECT

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • ConnectWise — ScreenConnect (abused as RAT)
    Vulnerable versions: All versions (legitimate tool abused)

Remediation for SILENTCONNECT

Immediate actions

  • Block domain bumptobabeco.top at perimeter firewalls and DNS
  • Block IP 86.38.225.59 at network perimeter
  • Block domains imansport.ir and solpru.com at DNS
  • Search for ScreenConnect services installed without IT approval
  • Hunt for VBScript files downloaded from internet in recent 90 days
  • Block outbound TCP port 8041 if not business-required

Workarounds

  • Disable Windows Script Host (wscript.exe/cscript.exe) for non-administrative users
  • Configure AppLocker or WDAC to block VBScript execution from user-writable directories
  • Restrict PowerShell to Constrained Language Mode for standard users
  • Block msiexec.exe from installing packages from internet-sourced paths

Longer-term hardening

  • Deploy EDR with behavioral detection for in-memory .NET compilation via Add-Type
  • Implement application whitelisting to prevent unauthorized VBScript and PowerShell execution
  • Monitor for PEB masquerading via ETW or kernel-level telemetry
  • Deploy AMSI-aware endpoint protection to inspect PowerShell and .NET runtime
  • Restrict CMSTPLUA COM object access via DCOM configuration
  • Implement RMM tool allowlisting — block unauthorized ScreenConnect and Syncro installations
  • Enable Windows Defender Tamper Protection to prevent exclusion additions

Timeline of SILENTCONNECT

  • Earliest known SILENTCONNECT campaign activity observed targeting Windows systems with VBScript-based lures
  • Campaign evolves to incorporate Cloudflare Turnstile CAPTCHAs for delivery gate and Google Drive for payload hosting
  • Malwarebytes publishes threat intel report on fake party invitation campaigns delivering remote access tools, overlapping with SILENTCONNECT activity
  • Elastic Security Labs identifies and names the SILENTCONNECT loader during investigation of ScreenConnect-based intrusions
  • Full technical analysis of SILENTCONNECT attack chain completed including PEB masquerading, CMSTPLUA UAC bypass, and in-memory compilation techniques
  • Elastic Security Labs publishes detailed technical research: From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect
  • Full indicator set published including SHA256 hashes, C2 domains (bumptobabeco.top), IP addresses (86.38.225.59), and YARA detection rules
  • Multiple security news outlets (CyberSecurityNews, GBHackers, CyberPress) publish coverage of SILENTCONNECT campaign and IOCs
  • Threat documented and published to Threadlinqs Intelligence Platform with full MITRE mappings, IOCs, and detection coverage
  • As of 2026-05-29, SILENTCONNECT remains an active, unattributed fileless loader campaign deploying ScreenConnect as a RAT, with no takedown or patch (a legitimate RMM is abused, no CVE). May 2026 reporting shows it ongoing and evolving: 150+ malicious domains since March 2026, AI-chatbot download poisoning in April, and new DLL-sideloading variants.

Sources cited for SILENTCONNECT

Detection coverage for TL-2026-0343

As of 2026-04-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0343 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats