Attackers Use Windows Screensavers to Drop Malware, RMM Tools
ID: 04027020-f1dc-55d8-bb42-dc4ff651d42e
STIX ID: report--04027020-f1dc-55d8-bb42-dc4ff651d42e
Feed Name: Dark Reading
Executive summary: ReliaQuest observed a campaign where attackers use Windows screensaver (.scr) files delivered via business-themed phishing lures and cloud-hosted links to install a legitimate RMM (JWrapper), giving attackers persistent interactive access to victims' systems; the technique leverages the fact that .scr files are PE executables and can bypass controls if not explicitly restricted. Observed impacts include potential data theft, lateral movement, and ransomware; recommended mitigations are treating .scr files as executables in application control, maintaining an approved RMM allowlist and alerting on unapproved RMM installations, and blocking non-business file-hosting services at the DNS or proxy layer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
