From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

A newly discovered loader called SILENTCONNECT is being used in active campaigns to silently install ScreenConnect, a remote monitoring and management tool, on victim machines. The infection chain begins with users being redirected to a Cloudflare Turnstile CAPTCHA page disguised as a digital invitation. Upon clicking, a VBScript file is downloaded, which retrieves and executes C# source code in memory using PowerShell. SILENTCONNECT employs various evasion techniques, including PEB masquerading and UAC bypass. The campaigns leverage trusted hosting providers like Google Drive and Cloudflare, and abuse living-off-the-land binaries. The loader has been active since March 2025 and poses a significant threat due to its stealthy nature and effectiveness.

Pulse ID: 69bbd761dff7b64814123d3f
Pulse Link: https://otx.alienvault.com/pulse/69bbd761dff7b64814123d3f
Pulse Author: AlienVault
Created: 2026-03-19 11:00:49

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CAPTCHA #Cloud #CyberSecurity #Google #InfoSec #Mac #OTX #OpenThreatExchange #PowerShell #RCE #Rust #ScreenConnect #VBS #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 151150Z AUTO 03013KT 9999 FEW074/// BKN091/// 14/07 Q1008” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #bresciaairport #airport #montichiari #italy #lipo #vbs #metar #aviation #aviationweather #avgeek vl
Brescia airport in Montichiari (Italy) aviation weather and informations LIPO VBS

Aviation weather with TAF and METAR, Maps, hotels and aeronautical information for Brescia airport in Montichiari (Italy)

Bigorre.org
Aviation weather for Brescia airport in Montichiari area (Italy) is “LIPO 041020Z AUTO 14003KT 100V180 5000 BR FEW008/// 13/10 Q1028” : See what it means on https://www.bigorre.org/aero/meteo/lipo/en #bresciaairport #airport #montichiari #italy #lipo #vbs #metar #aviation #aviationweather #avgeek vl
Brescia airport in Montichiari (Italy) aviation weather and informations LIPO VBS

Aviation weather with TAF and METAR, Maps, hotels and aeronautical information for Brescia airport in Montichiari (Italy)

Bigorre.org

...das #VBS als Sicherheitsrisiko 🫣

- Valeriya Novodvorskaya bezeichnete Putin (schon vor 2013, als der Bube in Moskau 'studierte') als Monster
- 2014 wurde die Krim überfallen
- usw., usw.

#CH #Politik #Landesverteidigung #Verrat

https://www.srf.ch/news/schweiz/heikle-russlandnaehe-appenzell-ausserrhoden-heuert-umstrittenen-ex-oberstleutnant-an

Russlandnähe: Ausserrhoden heuert umstrittenen Ex-Oberstleutnant

Ein Ex-Oberstleutnant ist auf dem Radar der Bundesbehörden. Dennoch erhält er eine sicherheitssensitive Anstellung.

Schweizer Radio und Fernsehen (SRF)

Cloud Atlas: Analysis of Phishing Campaign and VBShower Backdoor

Pulse ID: 699d3e7bfa78fc758cbaebfd
Pulse Link: https://otx.alienvault.com/pulse/699d3e7bfa78fc758cbaebfd
Pulse Author: Tr1sa111
Created: 2026-02-24 06:00:27

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Cloud #CloudAtlas #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #VBS #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Cloud Atlas: Analysis of Phishing Campaign and VBShower Backdoor

The article analyzes a phishing campaign by the Cloud Atlas APT group targeting Russian organizations. It details five successful attacks on the same system over time, using malicious Microsoft Office documents to deliver the VBShower backdoor. The attackers used alternate data streams to hide malicious code and maintained persistence through registry modifications. The analysis covers the evolution of the attack chain, including the use of VBCloud malware and various command and control servers. Despite prolonged access, no evidence of lateral movement was found. The report concludes that Cloud Atlas continues to be active, using consistent tactics and tools.

Pulse ID: 699c2539b33fbe17058937b3
Pulse Link: https://otx.alienvault.com/pulse/699c2539b33fbe17058937b3
Pulse Author: AlienVault
Created: 2026-02-23 10:00:25

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Cloud #CloudAtlas #CyberSecurity #ICS #InfoSec #Malware #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #Russia #VBS #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
Bei det 13. #AHV ist klar, was wir für's Geld bekommen - beim #VBS verschwindet es im Nirvana. (Lin Mi Marti)
Betrug und Unterschlagung im VBS/RUAG?
Nein, doch, oh 🤣🤣🤣🤣
verdammte vaganten!
#VBS kontrollieren, drecks schundladen!
https://www.srf.ch/news/schweiz/parlament-ruegt-regierung-ruag-betrugsfall-aufsicht-durch-bundesrat-war-haarstraeubend
Ruag-Betrugsfall: Aufsicht durch Bundesrat war «haarsträubend»

Schlechtes Zeugnis für die frühere VBS-Chefin Viola Amherd. Die GPK des Ständerats wirft ihr Sorglosigkeit vor.

Schweizer Radio und Fernsehen (SRF)

Engaged Buddhism: Vietnam Sangha Reports Charitable Impact Totaling US$82.3 Million in 2025

🔗 Read more: https://tinyurl.com/bp5ssdb4

#Buddhism #Vietnam #EngagedBuddhism #Charity #Compassion #VBS #HoChiMinh #Sangha

VBS-Hobby - 10% Gutschein

Beim Online-Shop VBS-Hobby könnt Ihr momentan mit diesem Gutscheincode 10% Rabatt auf Bastelbedarf erhalten. Rabattcode einfach einlösen und sparen!

Gutscheinportal Preishals