The campaign employs fake Zoom updates, business-document attachments, system-check tools, and Adobe update pages to trick users into installing attacker-controlled ScreenConnect agents This article explores malware campaign uses. . Once installed, these software programs give attackers remote desktop-style access that appears legitimate, mimicking authorized IT administration activity.
Since ScreenConnect is a signed and trusted enterprise tool, security products may consider it lower risk compared to traditional malware. The campaign uses various delivery methods, including VBScript files, batch scripts, compiled .NET loaders, malicious HTML pages, Dropbox links, and Cloudflare tunnels. Researchers linked the activity to a WsgiDAV staging server at 207.174.0.143:8080, which exposed payload files through an open directory listing during the investigation.
One script checked available system memory and searched for processes associated with malware analysis tools, including Wireshark, Process Monitor, VMware Tools, and VirtualBox services. Later versions became considerably more aggressive in their behavior. A file named SystemCheck employed a batch-based loader that aimed to circumvent the Antimalware Scan Interface, request elevated privileges, weaken SmartScreen protections, add Microsoft Defender exclusions, remove Mark-of-the-Web indicators, and silently install its payload.
The accompanying comment indicates this delay is meant to "Breaks Elastic correlation," implying attackers are actively testing methods to circumvent endpoint detection systems.












