216.73.216.6

Rogue ScreenConnect: Common Social Engineering Tactics Seen in 2025

· Published 31/12/2025 18:03 · Modified 02/01/2026 11:01

Export JSON

Essential information

Published
31/12/2025 18:03
Modified
02/01/2026 11:01
Tags
2025-12-31 lures remote access rmm abuse screenconnect social engineering
Related entities
14 observables, 10 techniques (mitre), 1 malware, 15 others

Description

In 2025, there was a significant increase in rogue installations, part of a broader trend of threat actors abusing remote monitoring and management tools (RMMs). These tools were used to gain access, blend in, move laterally, and maintain persistence in target systems. Attackers employed various tactics to trick employees into downloading malicious RMMs. Common included fake Social Security statements, invitations, and financial documents. The Huntress Security Operations Center identified recurring patterns in , domains, and file hashes associated with these attacks. Some campaigns showed signs of targeting specific industries, such as accounting firms. The article provides detailed examples of attack patterns, top malicious domains, and file hashes observed throughout the year.

External references