CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New Campaign Uses Screensavers for RMM-Based Persistence

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2206

As cited

Copy frozen at (site build).

ransomware

New Campaign Uses Screensavers for RMM-Based Persistence

ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.

Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

New Campaign Uses Screensavers for RMM-Based Persistence

ReliaQuest identified a spearphishing campaign delivering Windows screensaver (.scr) files that silently install legitimate remote monitoring and management (RMM) tools, granting attackers persistent interactive access. The attack uses business-themed email lures to trick users into downloading and executing .scr files from cloud storage platforms like GoFile, leveraging the trusted services and overlooked screensaver executable type to evade detection. The technique is repeatable, scalable, and enables attackers to escalate to credential theft, data exfiltration, and ransomware deployment.

Why it matters: Security teams need to immediately restrict .scr file execution from user-writable locations and implement approved-RMM allowlists with alerting, as this campaign exploits the conflation of legitimate remote-support software with attacker persistence infrastructure in ways that blend into normal IT operations.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary