Fake Party Invites Used To Lure Victims Into RAT Installation

Cybercriminals are tricking Windows users with seemingly harmless party invitations that secretly install ScreenConnect, a legitimate remote access tool (RAT).

This scam gives attackers full control over victims’ systems, turning casual clicks into major security breaches.

First spotted targeting UK users, the campaign could spread globally. Here’s how it unfolds, why it succeeds, and steps to fight back.

Attackers send informal emails posing as personal invites from friends or contacts often from hacked accounts.

The message feels casual and social, like “Hey, check out this party invite!” to bypass suspicion. A screenshot might show it arriving from a familiar sender.

Clicking the link redirects to a fake invitation page on domains like xnyr[.]digital. The page screams “You’re Invited!” with party-themed graphics, claims from a friend, and notes pushing Windows users.

A fake countdown hints the file is downloading, plus social proof like “I opened mine and it was so easy!” This auto-triggers a download of RSVPPartyInvitationCard.msi, making victims act fast without second thoughts.

Silent RAT Deployment and Persistent Access

The MSI isn’t a fun invite it’s an installer launching msiexec.exe. It quietly deploys ScreenConnect Client (a real IT support tool abused here) with no pop-ups, RSVPs, or calendar adds. Key actions include:

  • Installs binaries in C:\Program Files (x86)\ScreenConnect Client\
  • Creates a persistent Windows service, e.g., “ScreenConnect Client 18d1648b87bb3023” (randomized suffix)
  • Deploys multiple .NET components for stealth
Fake Invites Drop RATs (Source: Malwarebytes)
Fake Invites Drop RATs (Source: Malwarebytes)

From the user’s view, nothing obvious happens. But the client phones home via encrypted HTTPS to ScreenConnect relay servers and a unique attacker instance.

This grants god-like access: real-time screen viewing, mouse/keyboard control, file transfers, and persistence across reboots.

Detection lags because ScreenConnect looks legit. Early signs? Unexplained cursor moves, self-opening windows, or unfamiliar processes in Task Manager.

Indicator of Compromise (IOC)Description
RSVPPartyInvitationCard.msiMalicious MSI downloader
xnyr[.]digitalHosting domain for fake invites
ScreenConnect Client [random]Suspicious Windows service
C:\Program Files (x86)\ScreenConnect Client\Install path
Outbound HTTPS to ScreenConnect relaysNetwork beaconing

This hits human nature hard. Invites spark curiosity without red flags like urgency or bank alerts.

Security training focuses on aggressive phishing, not friendly social lures. By install time, it’s too late attackers lurk undetected.

Fake Invites Drop RATs (Source: Malwarebytes)
Fake Invites Drop RATs (Source: Malwarebytes)

Spot infection via:

  • Recent MSI named RSVPPartyInvitationCard.msi
  • New ScreenConnect Client install
  • Service with “ScreenConnect Client” plus random chars
  • Traffic to ScreenConnect domains
  • Behavioral oddities like rogue inputs

Protection Steps For Users and Orgs

Act fast RATs enable data theft, ransomware, or worse.

For Individuals:

  • Ignore unsolicited invites pushing downloads; verify via text/call.
  • Block MSI runs from email attachments.
  • If clicked: Disconnect internet, scan with antivirus, uninstall ScreenConnect via Apps & Features, reset passwords from a clean device.

For Organizations (UK-Focused but Global Risk):

  • Block unauthorized ScreenConnect via endpoint tools.
  • Restrict MSI execution with AppLocker or policies.
  • Flag remote tools as high-risk; scan for them routinely.
  • Train staff: Invites aren’t installers report suspicious emails.

Tools like Malwarebytes now catch this by alerting on surprise RAT installs, letting you approve or nuke them. Stay vigilant scammers evolve, but awareness blocks the door.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories