Beware of Malicious Party Invitations that Tricks Users into Installing Remote Access Tools
A recent phishing campaign has been identified, utilizing fake party invitations to install remote access software on Windows systems. The campaign employs social engineering tactics to deploy ScreenConnect, a legitimate remote support tool, allowing…
A recent phishing campaign has been identified, utilizing fake party invitations to install remote access software on Windows systems. The campaign employs social engineering tactics to deploy ScreenConnect, a legitimate remote support tool, allowing unauthorized access to compromised systems.
The phishing attempt masquerades as an invitation from a familiar contact, leading recipients to believe it is a benign message. This approach leverages compromised email accounts, enhancing the authenticity of the invitation. The informal style of the email reduces suspicion, prompting recipients to interact with the message.
Upon clicking the email's link, victims are directed to a webpage that mimics a legitimate event invitation. The page features a countdown timer and social proof statements to encourage users to download a file named RSVPPartyInvitationCard.msi.
The MSI file is an installer for ScreenConnect, which is surreptitiously installed via Windows Installer (msiexec.exe). The installation process lacks clear notifications, leaving users unaware of the action. The ScreenConnect binaries are installed in the directory C:\Program Files (x86)\ScreenConnect Client\ and initiate a persistent Windows service with a randomized name.
A recent phishing campaign has been identified, utilizing fake party invitations to install remote access software on Windows systems.
Once installed, ScreenConnect establishes encrypted HTTPS connections to relay servers, granting attackers full remote access capabilities. This includes real-time screen viewing, file transfers, and persistent control, even after system reboots.
The software's legitimate nature means traditional security tools may not flag it as a threat. Indicators of compromise include unexpected cursor movements, unauthorized window activity, and unrecognized background processes.
For further information on the technical aspects and potential security measures, please refer to the detailed report .
Based on reporting by Cyber Security News.
