logo

Attackers Use Windows Screensavers to Drop Malware, RMM Tools

ID: 04027020-f1dc-55d8-bb42-dc4ff651d42e

STIX ID: report--04027020-f1dc-55d8-bb42-dc4ff651d42e

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Executive summary: ReliaQuest observed a campaign where attackers use Windows screensaver (.scr) files delivered via business-themed phishing lures and cloud-hosted links to install a legitimate RMM (JWrapper), giving attackers persistent interactive access to victims' systems; the technique leverages the fact that .scr files are PE executables and can bypass controls if not explicitly restricted. Observed impacts include potential data theft, lateral movement, and ransomware; recommended mitigations are treating .scr files as executables in application control, maintaining an approved RMM allowlist and alerting on unapproved RMM installations, and blocking non-business file-hosting services at the DNS or proxy layer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.