Researchers reported that Operation SilentCanvas is using weaponized .jpeg files to compromise Windows systems and deploy a trojanized ConnectWise ScreenConnect remote access tool. In the campaign, a file such as sysupdate.jpeg is actually a PowerShell loader delivered through social engineering, including phishing, deceptive file-sharing, and fake software updates. The malware creates a staging directory at C:\Systems, downloads additional payloads from legitserver.theworkpc[.]com over TCP port 5443, and compiles a custom launcher named uds.exe on the victim host using csc.exe.
The intrusion chain includes runtime string reconstruction, in-memory execution of a secondary payload, AMSI bypass, and a UAC bypass that abuses the ms-settings registry path and launches ComputerDefaults.exe to gain elevated privileges without a visible prompt. Once installed, the malware enables persistent remote access, credential theft, encrypted command-and-control, screen capture, microphone monitoring, hidden desktop execution, and long-term persistence through a Windows service named OneDriveServers and hidden administrator accounts. Defenders were urged to monitor abused Windows binaries, investigate suspicious PowerShell and unexpected ScreenConnect activity, tightly control remote administration tools, isolate affected hosts, and reset privileged credentials after suspected compromise.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Symantec publicly reported that the early-2026 intrusions were linked to Seedworm and described the group's use of legitimate signed binaries, attacker-controlled infrastructure, and public file-transfer services for espionage and data exfiltration.
Cyfirma disclosed that the SilentCanvas intrusion chain downloads a trojanized ConnectWise ScreenConnect package, compiles a custom launcher on the victim host, bypasses AMSI and UAC, and establishes long-term persistence through a Windows service and hidden administrator accounts.
By May 2026, Cyfirma analyzed a campaign dubbed Operation SilentCanvas in which attackers used a weaponized file named sysupdate.jpeg, actually a PowerShell loader, to compromise Windows systems through likely phishing, deceptive file-sharing, or fake software updates.
In February 2026, Seedworm breached a major South Korean electronics manufacturer for roughly one week, using DLL sideloading, Node.js-based loaders, PowerShell, credential theft tools, privilege escalation tooling, and screenshot capture to maintain access and collect intelligence.
In early 2026, the Iran-linked group Seedworm carried out an espionage campaign affecting at least nine organizations in nine countries across four continents, targeting sectors including manufacturing, government, education, financial services, and professional services.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurity.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.