Windows Screensaver Hijacked For Remote Access and RMM Tool Deployment

Attackers have launched a spearphishing campaign that abuses Windows screensaver (.scr) files to install legitimate remote monitoring and management (RMM) tools, granting persistent remote access without triggering classic malware alerts.

This technique blends into normal IT operations, allowing escalation to credential theft, data exfiltration, or ransomware. ReliaQuest first spotted this across multiple customers, noting its novelty in using business-themed lures for .scr downloads.

Attack Chain Breakdown

The campaign begins with spearphishing emails that link to cloud storage services like GoFile, hosting .scr files disguised as documents such as “InvoiceDetails.scr”.

According to ReliaQuest, users download and execute these from the Downloads folder, bypassing many security tools that focus on .exe or .msi extensions.

Execution silently installs an RMM agent, like SimpleHelp via JWrapper, creating artifacts in C:\ProgramData\JWrapper-Remote Access\ and initiating outbound connections to attacker-controlled servers.

This RMM provides interactive, reboot-surviving access for lateral movement, data theft, or ransomware staging.

Attackers exploit trusted services to mimic routine operations, delaying detection. The method is adaptable swap hosting or RMM tools while keeping the playbook intact.

Screensaver files are portable executables (PE) that run arbitrary code, yet users and policies often overlook them as harmless.

RMM tools, designed for IT with elevated privileges and encrypted channels, blend in when ungoverned. This “living-off-the-land” approach reduces the need for custom malware.

Prior cases confirm the viability: In August 2025, .scr files dropped the GodRAT RAT via financial phishing apps.

In June 2025, DragonForce ransomware exploited MSP RMM flaws to establish persistence and encrypt data, per CISA. These show scalable abuse of overlooked formats and tools.

Treat .scr files as untrusted executables: Block execution from Downloads, Desktop, or Temp using AppLocker, WDAC, or equivalents; allow only signed paths.

Govern RMM with allowlists (vendors, certs, hashes); alert on new services, tasks, or ProgramData folders post-execution.​

Attackers will evolve, targeting other overlooked formats or archives, bypassing extension blocks.

RMM abuse persists in weak governance setups, fueling ransomware. Prioritize context over signatures prove intent via behavior. Strong controls make this path unreliable.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories