logo

Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025

ID: 51be7fd4-33ce-54dd-84c8-25722dd78f0e

STIX ID: report--51be7fd4-33ce-54dd-84c8-25722dd78f0e

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-12-31

Date Updated: 2026-04-28

...
...

Huntress reports an uptick in 2025 of threat actors abusing remote monitoring and management tools—particularly rogue ScreenConnect installers—delivered via phishing lures (invoices, Social Security statements, event invitations) to obtain remote access. The post documents multiple IoCs (domains, SHA256 hashes, filenames), shows domain reuse across many customer accounts (notably targeting accounting firms), illustrates real SOC detections, and provides mitigation guidance such as auditing RMMs, monitoring logs, patching, and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.