As cited
Copy frozen at (site build).
ransomware
New Campaign Uses Screensavers for RMM-Based Persistence
ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.
Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
New Campaign Uses Screensavers for RMM-Based Persistence
ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.
Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.
- Source published
- First seen by Cybersecurity Tracker