New Campaign Uses Screensavers for RMM-Based Persistence
ID: 67cb0e8f-4a97-5b67-8b37-3d0822657011
STIX ID: report--67cb0e8f-4a97-5b67-8b37-3d0822657011
Feed Name: ReliaQuest Blog
ReliaQuest details a spearphishing campaign where business-themed lures lead targets to download .scr screensaver executables from consumer cloud hosts; executing the .scr silently installs legitimate RMM agents (artifacts observed under C:\ProgramData\JWrapper-Remote Access) that give attackers persistent, encrypted remote access enabling discovery, data exfiltration, lateral movement, and potential ransomware—the report emphasizes treating .scr as executables, enforcing approved-RMM allowlists, and restricting consumer file-hosting and downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
