Skip to main content

OPERATION SILENTCANVAS: JPEG BASED MULTISTAGE POWERSHELL INTRUSION

0
Medium
Published: 05/10/2026 (05/10/2026, 13:09:22 UTC)
Source: AlienVault OTX General

Description

A sophisticated multi-stage intrusion campaign was identified leveraging a weaponized PowerShell payload disguised as a JPEG image file (sysupdate.jpeg) to deploy a trojanized ConnectWise ScreenConnect instance for covert remote access. The attack likely originates through social engineering techniques including phishing emails or malicious attachments. Upon execution, the malware establishes a staging environment, retrieves additional payloads from attacker-controlled infrastructure, and dynamically compiles a custom launcher using Microsoft's legitimate .NET compiler (csc.exe) to evade detection. The intrusion abuses ComputerDefaults.exe and a malicious ms-settings registry hijack to perform a fileless UAC bypass and obtain elevated privileges. Once elevated, the malware deploys a persistent service masquerading as OneDriveServers and launches a modified ScreenConnect framework capable of credential interception, remote command execution, surveillance operations, SYSTEM-level execution, encrypted command...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/11/2026, 10:22:50 UTC

Technical Analysis

Operation SilentCanvas is a multi-stage intrusion campaign leveraging a weaponized PowerShell payload hidden as a JPEG image (sysupdate.jpeg). Initial infection vectors likely include phishing or malicious attachments. The malware establishes a staging environment, retrieves further payloads from attacker-controlled infrastructure, and uses the legitimate .NET compiler (csc.exe) to dynamically compile a custom launcher, aiding evasion. It abuses ComputerDefaults.exe and a malicious ms-settings registry hijack to perform a fileless UAC bypass, gaining elevated privileges without triggering typical defenses. Post-elevation, it deploys a persistent service disguised as OneDriveServers and launches a trojanized ConnectWise ScreenConnect instance modified for credential interception, remote command execution, surveillance, and SYSTEM-level code execution. The campaign uses fileless execution and AMSI bypass techniques to avoid detection. Indicators include multiple file hashes and a domain (legitserver.theworkpc.com). There is no CVE or vendor patch information, and no known exploits in the wild have been reported.

Potential Impact

The campaign enables attackers to gain covert remote access with SYSTEM-level privileges, allowing credential theft, remote command execution, and surveillance operations. The use of fileless execution and legitimate Windows binaries for privilege escalation and evasion increases the difficulty of detection and mitigation. The trojanized ConnectWise ScreenConnect instance provides a persistent backdoor for attackers. Although no known exploits in the wild are reported, the campaign poses a medium severity threat due to its sophisticated techniques and potential for extensive system compromise.

Defensive Guidance

No official patch or remediation guidance is currently available for this campaign. Organizations should rely on threat intelligence to detect indicators of compromise such as the provided file hashes and domain names. Since the attack uses social engineering vectors, user awareness training to recognize phishing attempts is recommended. Monitoring for abuse of legitimate Windows binaries (e.g., ComputerDefaults.exe, csc.exe) and registry hijacks related to ms-settings may help identify suspicious activity. Because the campaign employs fileless techniques and AMSI bypass, endpoint detection and response solutions with behavioral analysis capabilities may improve detection. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cyfirma.com/research/operation-silentcanvas-jpeg-based-multistage-powershell-intrusion/"]
Pulse Id
6a008382641183db3b20fef5

Indicators of Compromise

Domain

ValueDescriptionCopy
domainlegitserver.theworkpc.com
—

Hash

ValueDescriptionCopy
hash7adffc1c0b3fdcba46e8d0a81203c955976d4ef39893c98d0b2dbfbb8d6a8ec3
—
hashee3d776cdaf82335e4293e19ee313cc35eee49cde9963b96766a8f9c89d44a79
—
hash752a7188f2bab1926a63254e29f3108a
—
hash7dd05336097e5a833f03a63d3221494f
—
hasha40e6ca64bbeaf7e42100371defa2c51
—
hashcdc55f204dd2d7e2240d5b785250e68d
—
hashfcb58cddda40825616c70c93b312a79a
—
hash19e1234a94f0445e8fdb9ae0f75554292db48c1c
—
hash3cf97b5207e51a1ae8e640450279abef204f0466
—
hash94acd6b46cce2a0b84cc5efad3e661eeaa58a612
—
hash98661a28d73703ec3728e8f9b25dfab043f4ca6f
—
hash4d8ac85c5b98c69ba44146df61183e9bf613edd796aa516c3ae73611b7d77c06
—
hasha635f0c94c98b658ae799978994f0d0a292567cd97b8a19068a8423d1297652a
—
hashcea1d85967d2c456fccecae3a70ff2adfe4c113aacf9d18c35906c2ed24ca9b4
—
hashe4c9f3bb4a65c640795bfc1a56c0b56485b849ccd97027eed7ad9aa78a732a4f
—
hashecd5ed16975d556d1d17bc980f248f8a5262bed11df9d9cf999efd9c273c11df
—
hash21c1e7557b13a63c2c87ca29c701347553077268
—
hash91451c9755494a1151763764d96a3178002b367d
—
hashaf525cbdf7ba92921d05593bc35a81528ffa1083
—

Threat ID: 6a01aa1fcbff5d8610f2b582

Added to database: 05/11/2026, 10:06:23 UTC

Last enriched: 05/11/2026, 10:22:50 UTC

Last updated: 09/21/2026, 22:15:16 UTC

Views: 280

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses