Cybercriminals are tricking Windows users with seemingly harmless party invitations that secretly install ScreenConnect, a legitimate remote access tool (RAT).
This scam gives attackers full control over victims’ systems, turning casual clicks into major security breaches.
First spotted targeting UK users, the campaign could spread globally. Here’s how it unfolds, why it succeeds, and steps to fight back.
Attackers send informal emails posing as personal invites from friends or contacts often from hacked accounts.
The message feels casual and social, like “Hey, check out this party invite!” to bypass suspicion. A screenshot might show it arriving from a familiar sender.
Clicking the link redirects to a fake invitation page on domains like xnyr[.]digital. The page screams “You’re Invited!” with party-themed graphics, claims from a friend, and notes pushing Windows users.
A fake countdown hints the file is downloading, plus social proof like “I opened mine and it was so easy!” This auto-triggers a download of RSVPPartyInvitationCard.msi, making victims act fast without second thoughts.
Silent RAT Deployment and Persistent Access
The MSI isn’t a fun invite it’s an installer launching msiexec.exe. It quietly deploys ScreenConnect Client (a real IT support tool abused here) with no pop-ups, RSVPs, or calendar adds. Key actions include:
- Installs binaries in
C:\Program Files (x86)\ScreenConnect Client\ - Creates a persistent Windows service, e.g., “ScreenConnect Client 18d1648b87bb3023” (randomized suffix)
- Deploys multiple .NET components for stealth

From the user’s view, nothing obvious happens. But the client phones home via encrypted HTTPS to ScreenConnect relay servers and a unique attacker instance.
This grants god-like access: real-time screen viewing, mouse/keyboard control, file transfers, and persistence across reboots.
Detection lags because ScreenConnect looks legit. Early signs? Unexplained cursor moves, self-opening windows, or unfamiliar processes in Task Manager.
| Indicator of Compromise (IOC) | Description |
|---|---|
| RSVPPartyInvitationCard.msi | Malicious MSI downloader |
| xnyr[.]digital | Hosting domain for fake invites |
| ScreenConnect Client [random] | Suspicious Windows service |
| C:\Program Files (x86)\ScreenConnect Client\ | Install path |
| Outbound HTTPS to ScreenConnect relays | Network beaconing |
This hits human nature hard. Invites spark curiosity without red flags like urgency or bank alerts.
Security training focuses on aggressive phishing, not friendly social lures. By install time, it’s too late attackers lurk undetected.

Spot infection via:
- Recent MSI named RSVPPartyInvitationCard.msi
- New ScreenConnect Client install
- Service with “ScreenConnect Client” plus random chars
- Traffic to ScreenConnect domains
- Behavioral oddities like rogue inputs
Protection Steps For Users and Orgs
Act fast RATs enable data theft, ransomware, or worse.
For Individuals:
- Ignore unsolicited invites pushing downloads; verify via text/call.
- Block MSI runs from email attachments.
- If clicked: Disconnect internet, scan with antivirus, uninstall ScreenConnect via Apps & Features, reset passwords from a clean device.
For Organizations (UK-Focused but Global Risk):
- Block unauthorized ScreenConnect via endpoint tools.
- Restrict MSI execution with AppLocker or policies.
- Flag remote tools as high-risk; scan for them routinely.
- Train staff: Invites aren’t installers report suspicious emails.
Tools like Malwarebytes now catch this by alerting on surprise RAT installs, letting you approve or nuke them. Stay vigilant scammers evolve, but awareness blocks the door.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.