Security1 distinct publisher2 min readPublished
Trinity Cyber's deception workstation caught the same operator installing ScreenConnect from a batch file, reaching into LSASS by hand, then dropping FormBook into a signed binary. Two detection teams usually own those halves separately.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The parent process is where this becomes a detection rule. ScreenConnect's RunFile capability executed HideUL_x64.exe, Password.exe, Opencamera.exe and a wrapper that opened Phone Link through the ms-phone: handler, with ScreenConnect.WindowsClient.exe as the parent in every case [7]. Deception.Pro also recorded LSASS access from wmiprvse.exe 45 times and from ScreenConnect.ClientService.exe seven times, one of those with a full-rights handle [8]. An RMM service process holding a full-rights handle on LSASS is the highest-value line in the whole capture.
The tooling arrived in two visits. HideUL_x64.exe dropped its temp file at 22:29 on August 6 by the EDR clock, and Password.exe, Opencamera.exe and phonepcNew (1).exe all ran at 12:54 on August 8 [7]. That is a gap of 38 hours and 25 minutes [13], which is an operator who kept a foothold, went away, and came back to do collection in one burst. The roughly 75 MB of outbound traffic on the secondary relay at 185.241.149.220:8041 fits a sustained interactive session rather than a beacon [6].
The automated half is noisier and cheaper to spot. Spread across the full 54-hour window, 19,284 GET check-ins average one every 10 seconds [14], and because FormBook only started calling home after the operator deployed it, the live rate was faster than that. The GET-to-POST ratio is about 75 to 1 [15]: the 256-plus POSTs are the stolen form data, and the rest is check-in traffic diluted deliberately, since the 63-domain set mixes actor infrastructure with beacons to legitimate domains [11]. The form-grabber's target list ran through Fidelity, Chase, Bank of America, Schwab, Vanguard, PayPal and others, with staging and upload to Sendspace, which Suricata flagged as a Sendspace API upload [12].
On novelty, read the scope carefully. Deception.Pro says the co-occurrence of interactive ScreenConnect operator access and automated XLoader deployment in one coordinated intrusion is first-observed in its own collection [2], which is a statement about one telemetry set and not a claim about the wild. No actor or crew is named in the report. The environment was a deception workstation run by Trinity Cyber, so nothing here describes damage to a production estate [3].
Two of the network indicators were already covered: Suricata fired both on the bare-IP curl to a non-standard port and on the ET HUNTING rule for a silent ScreenConnect MSI install [5]. Rotating 172.245.23.152 and 185.241.149.220 costs the operator an afternoon [6], while the RunFile parent relationship [7] and the four-character URI with a spoofed Android 4.4.4 user-agent [10] survive re-tooling.
Ranked by verification strength, evidence, and original report placement.
Over a roughly 54-hour window in early August 2026, an operator engaged a Deception.Pro deception workstation and executed a near-complete intrusion chain from a PDF-themed phish through automated infostealer C2; the lure delivered a batch downloader that silently side-loaded ConnectWise ScreenConnect from attacker infrastructure.
Deception.Pro states that the co-occurrence of interactive ScreenConnect operator access and automated XLoader/FormBook deployment in a single coordinated intrusion is a first-observed pattern in its collection.
Trinity Cyber ran the deception operation that captured the intrusion, operating in the Deception.Pro environment across the full engagement window; analysis and telemetry reconstruction were done by Deception.Pro Threat Research.
The user ran Project_docs_file.bat from the browser Downloads folder, spawned from chrome.exe behind a PDF-themed lure; the script fingerprinted the host with net session and temp/dir enumeration, probed 172.245.244.73 on port 8040 with Test-NetConnection, then used curl to pull ScreenConnect.ClientSetup.msi from 172.245.23.152:8040.
Suricata fired on the bare-IP curl to a non-standard port and on the rule 'ET HUNTING Silent ScreenConnect Install (.msi)'.
The MSI installed ScreenConnect as a persistent service and the operator deployed two independent relay instances pointing at separate C2 endpoints for redundant hands-on control: primary relay 172.245.23.152:8041 and secondary relay 185.241.149.220:8041, with the secondary carrying the bulk of interactive traffic at roughly 75 MB outbound.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Attackers reached a domain controller through one exposed SolarWinds helpdesk1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
build
AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Granular but unwitnessed
The artefact density is unusually high for a vendor write-up: named binaries, relay ports, ATT&CK mappings, YARA rule names, LSASS access counts and timestamps to the minute. All of it rests on one telemetry set that only Deception.Pro can see, and the one interpretive claim — that this pairing has not been seen before — is bounded by its own collection. Precision and independence are different things, and this story has the first without the second.
One capture, no prevalence
The observed world here is a single 54-hour engagement on one instrumented decoy. Deception.Pro offers no second case, no frequency, and no indication whether other operators in the same honeynet have paired remote-management access with a stealer. A pattern seen once is a lead, not a trend, and the report says as much when it calls the pairing first-observed.
Hedged claim, promotional frame
Deception.Pro hedges where it matters — 'in our collection', 'either a single actor or an access-broker handoff' — and that restraint keeps the gap small. What pushes it above zero is the packaging: a first-of-its-kind headline built on one decoy host, ending in a pitch to run operations in the same environment, with defenders told to build a new detection signature on the strength of a single session.
Vendor telemetry, vendor pitch
Deception.Pro sells the honeynets that produced this telemetry and says so plainly, crediting partner Trinity Cyber up front and closing with 'Interested in running operations like these?'. Disclosure is not neutrality: the same firm chooses which engagements are worth writing up, defines what counts as never-before-seen, and benefits when the answer is yes. The technical detail is too checkable to be invented, but the selection and framing are not disinterested.
Trust the artefacts, hold the finding
Split the story in two and confidence splits with it. The forensic layer — file names, ports, rule hits, injection targets — is stated with enough specificity that a defender can act on it today and find out quickly if it is wrong. The headline conclusion, that manual remote-management abuse and commodity form-grabbing now arrive together, is one observation from one interested observer and should hold provisionally until someone outside this environment sees the same shape.