logo

Phishing Campaign Abuses eCards to Deploy RMM Tools

ID: d3a3df09-2b9e-565a-a5f1-738ccbc7ba86

STIX ID: report--d3a3df09-2b9e-565a-a5f1-738ccbc7ba86

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

Forescout reported a six-month phishing campaign called SeasonalInvite that lured Windows and macOS users with calendar-themed eCards to download legitimately signed RMM installers (ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, O&O Syspectr). The operation used a traffic distribution system and hundreds of domains to serve OS-specific installers—abusing UAC prompts and unattended-enrollment features to redirect victims to attacker-controlled consoles—and showed signs of an LLM-assembled kit; Forescout recommends whitelisting approved RMMs, tightening email defenses, and training staff to never install remote support software from eCards.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.