logo

New Campaign Uses Screensavers for RMM-Based Persistence

ID: 67cb0e8f-4a97-5b67-8b37-3d0822657011

STIX ID: report--67cb0e8f-4a97-5b67-8b37-3d0822657011

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-29

...
...

ReliaQuest details a spearphishing campaign where business-themed lures lead targets to download .scr screensaver executables from consumer cloud hosts; executing the .scr silently installs legitimate RMM agents (artifacts observed under C:\ProgramData\JWrapper-Remote Access) that give attackers persistent, encrypted remote access enabling discovery, data exfiltration, lateral movement, and potential ransomware—the report emphasizes treating .scr as executables, enforcing approved-RMM allowlists, and restricting consumer file-hosting and downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.