Phishing

Windows screensaver files weaponized in spearphishing campaign

Attacks leveraging Windows screensaver files to facilitate clandestine delivery of remote monitoring and management tools have been launched against multiple organizations as part of a spearphishing campaign, reports Cybernews.

Threat actors have targeted employees with business-themed emails containing screensaver files purporting to be invoice details or project summaries that stealthily install legitimate RMM tools upon opening, according to ReliaQuest researchers. Installation of the RMM agent provides persistent access and possible command-and-control capabilities that could facilitate subsequent privilege escalation, credential harvesting, lateral movement, data theft, and ransomware deployment. Such an attack technique was regarded as novel by researchers, who emphasized its repeatability and adaptability.

"If RMM agents can be installed without strong governance, monitoring, and rapid containment, attackers will continue to treat them as a reliable path to persistence and a launchpad for ransomware and data theft," said researchers, who recommended increased vigilance on remote access tools and outbound connections.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds