logo

Hackers Exploit Windows Screensaver to Deploy RMM Tools, Gain Remote Access

ID: 1029fc11-fc7a-594d-ba1f-dcccf9f4b471

STIX ID: report--1029fc11-fc7a-594d-ba1f-dcccf9f4b471

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

## Executive summary A spear-phishing campaign is distributing Windows screensaver (.scr) files hosted on public file-sharing platforms; when executed, these PE-format files deploy legitimate RMM agents (such as SimpleHelp) to establish persistent, stealthy remote access. The report highlights evasion due to trust in RMM software and recommends blocking .scr execution from user-writable directories, allowlisting authorized RMMs, and monitoring for artifacts like unexpected scheduled tasks, services, or ProgramData folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.