# SILENTCONNECT: Fileless In-Memory .NET Loader Delivers ScreenConnect RAT via VBScript, PEB Masquerading, and UAC Bypass

> SILENTCONNECT is a multi-stage fileless loader campaign active since March 2025 that uses VBScript lures disguised as digital invitations to download C# source code from Google Drive, compile it in-memory via PowerShell Add-Type, perform PEB masquerading and CMSTPLUA COM UAC bypass, then silently deploy ConnectWise ScreenConnect RMM as a persistent backdoor with C2 over TCP port 8041.

- **Published:** 2026-04-09T12:00:00Z
- **Last reviewed:** 2026-04-09T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0343
- **ID:** TL-2026-0343
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

SILENTCONNECT is a sophisticated multi-stage fileless malware loader campaign first observed in March 2025 and publicly disclosed by Elastic Security Labs in March 2026. The campaign targets Windows systems through social engineering, using phishing emails with fake digital invitations (party invitations, DocuSign documents, Microsoft Teams meeting links) to lure victims into executing malicious VBScript files.

The infection chain begins when a victim clicks a link in a phishing email, which redirects through a Cloudflare Turnstile CAPTCHA page — a technique used to evade automated analysis and add legitimacy. After completing the CAPTCHA, the victim downloads a VBScript file (commonly named E-INVITE.vbs or themed after legitimate documents like 'Alaska Airlines 2026 Fleet & Route Expansion Summary.vbs'). The VBScript files are minimally obfuscated, using a children's story as decoy text and employing Replace() and Chr() functions for de-obfuscation.

Upon execution, the VBScript spawns PowerShell with -ExecutionPolicy Bypass, which uses the built-in curl.exe (a living-off-the-land binary) to download a C# source file named FileR.txt from Google Drive. This C# payload is then compiled and executed entirely in-memory using the PowerShell Add-Type cmdlet, leaving no malicious executable on disk — a key evasion technique that defeats most traditional endpoint security tools.

The compiled SILENTCONNECT loader incorporates several advanced evasion techniques. It implements a 15-second sleep delay before payload execution to evade sandbox analysis. It performs PEB (Process Environment Block) masquerading by locating its own module list entry and overwriting both the BaseDLLName and FullDllName fields to display winhlp32.exe and c:\windows\winhlp32.exe respectively, making the malicious process appear as a legitimate Windows binary to security tools that inspect PEB data. The loader uses direct NTAPI calls through ntdll.dll and ole32.dll rather than higher-level Windows APIs, further evading API-level monitoring. The C# payload employs constant unfolding to conceal byte arrays and stores launch parameters in reverse character array order as additional obfuscation.

For privilege escalation, SILENTCONNECT performs a UAC bypass through the CMSTPLUA COM interface, using the LaunchElevatedCOMObjectUnsafe function. The elevation moniker string is stored reversed as ':wen!rotartsinimdA:noitavelE' to evade static detection. Once elevated, the loader adds a Windows Defender exclusion for .exe files via WMI, effectively neutering real-time protection for all executable files.

The final payload is a ConnectWise ScreenConnect (formerly ConnectWise Control) MSI installer, downloaded from the attacker-controlled domain bumptobabeco.top and silently installed via msiexec. ScreenConnect persists as a Windows service and establishes command-and-control communication over TCP port 8041 to bumptobabeco.top, with relay infrastructure at instance-lh1907-relay.screenconnect.com. An alternative exploitation path using Syncro RMM (ViewDocs.exe) has also been identified.

The threat actor demonstrates poor operational security, reusing the URI path download_invitee.php across multiple compromised websites (including imansport.ir and solpru.com). Infrastructure abuses trusted providers including Cloudflare for CAPTCHA delivery and Google Drive for payload hosting. The phishing sender domain checkfirst.net.au with sender dan@checkfirst.net.au has been identified across multiple lures.

## MITRE ATT&CK

- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1106 Native API
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1218 System Binary Proxy Execution
- T1140 Deobfuscate/Decode Files or Information
- T1219 Remote Access Tools
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol
- T1102 Web Service
- T1584 Compromise Infrastructure
- T1608 Stage Capabilities

## Sources

- [From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect — Elastic Security Labs](https://www.elastic.co/security-labs/silentconnect-delivers-screenconnect)
- [SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect](https://cybersecuritynews.com/silentconnect-uses-vbscript-powershell/)
- [SilentConnect Uses Fake Invites to Deploy ScreenConnect RAT](https://gbhackers.com/screenconnect-rat/)
- [Fake Invitations Fuel SILENTCONNECT Campaign Delivering ScreenConnect RAT](https://cyberpress.org/silentconnect-delivers-screenconnect-rat/)
- [ScreenConnect Deployed via SILENTCONNECT Using VBScript and PEB Masquerading](https://cyberpress.org/silentconnect-drops-screenconnect-stealthily/)
- [How Fake Party Invitations Are Being Used to Install Remote Access Tools — Malwarebytes](https://www.malwarebytes.com/blog/threat-intel/2026/02/how-fake-party-invitations-are-being-used-to-install-remote-access-tools)
- [Advisory Alert: Surge in ScreenConnect Malware — Lumu](https://lumu.io/blog/connectwise-screenconnect-malware/)
- [SILENTCONNECT Threat Report — OffSeq Threat Radar](https://radar.offseq.com/threat/from-invitation-to-infection-how-silentconnect-del-4ebdc8bf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0343
