Beware of Malicious Party Invitations that Tricks Users into Installing Remote Access Tools
ID: 0b5e20fa-58ef-51b5-8485-1e776774ee15
STIX ID: report--0b5e20fa-58ef-51b5-8485-1e776774ee15
Feed Name: cybersecurityNews.com
Threat Score
A phishing campaign targets primarily UK users with convincing party-invitation emails that deliver an MSI installer (RSVPPartyInvitationCard.msi); the installer silently deploys legitimate ScreenConnect remote-access software under C:\Program Files (x86)\ScreenConnect Client\ and creates a persistent service with randomized names, enabling attackers to remotely view and control victims' systems while evading some security tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
