Attacks leveraging Windows screensaver files to facilitate clandestine delivery of remote monitoring and management tools have been launched against multiple organizations as part of a spearphishing campaign, reports Cybernews.Threat actors have targeted employees with business-themed emails containing screensaver files purporting to be invoice details or project summaries that stealthily install legitimate RMM tools upon opening, according to ReliaQuest researchers. Installation of the RMM agent provides persistent access and possible command-and-control capabilities that could facilitate subsequent privilege escalation, credential harvesting, lateral movement, data theft, and ransomware deployment. Such an attack technique was regarded as novel by researchers, who emphasized its repeatability and adaptability."If RMM agents can be installed without strong governance, monitoring, and rapid containment, attackers will continue to treat them as a reliable path to persistence and a launchpad for ransomware and data theft," said researchers, who recommended increased vigilance on remote access tools and outbound connections.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




