Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025
ID: 51be7fd4-33ce-54dd-84c8-25722dd78f0e
STIX ID: report--51be7fd4-33ce-54dd-84c8-25722dd78f0e
Feed Name: Huntress Blog
Huntress reports an uptick in 2025 of threat actors abusing remote monitoring and management tools—particularly rogue ScreenConnect installers—delivered via phishing lures (invoices, Social Security statements, event invitations) to obtain remote access. The post documents multiple IoCs (domains, SHA256 hashes, filenames), shows domain reuse across many customer accounts (notably targeting accounting firms), illustrates real SOC detections, and provides mitigation guidance such as auditing RMMs, monitoring logs, patching, and security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
