

15·
4 months agoThe embedded PowerShell code creates a hidden folder at C:\Systems and downloads a trojanized ScreenConnect package from legitserver.theworkpc[.]com over TCP port 5443.
Nothing to see here, just a legit server doing work with the systems.




Cool that they’re switching to Wayland by default - I’ll be curious what the general reaction is