Rogue ScreenConnect: Common Social Engineering Tactics Seen in 2025
Jan. 2, 2026, 11:01 a.m.
Description
In 2025, there was a significant increase in rogue ScreenConnect installations, part of a broader trend of threat actors abusing remote monitoring and management tools (RMMs). These tools were used to gain access, blend in, move laterally, and maintain persistence in target systems. Attackers employed various social engineering tactics to trick employees into downloading malicious RMMs. Common lures included fake Social Security statements, invitations, and financial documents. The Huntress Security Operations Center identified recurring patterns in lures, domains, and file hashes associated with these attacks. Some campaigns showed signs of targeting specific industries, such as accounting firms. The article provides detailed examples of attack patterns, top malicious domains, and file hashes observed throughout the year.
Tags
Date
- Created: Dec. 31, 2025, 6:03 p.m.
- Published: Dec. 31, 2025, 6:03 p.m.
- Modified: Jan. 2, 2026, 11:01 a.m.
Indicators
- 7fdfe8b34ad911fa007d9f2c8b2cb99cea0ac760d23643850a72e75cf8aa62c3
- a3e314dc43a4410e9bc8d93b27da8a7764138c6b453b8eb5fb6845f948901cf6
- 82cb1fee5f4a7420d378efe0c4a9fc52d547208cb04c87d17c37b714778c9935
- 9d6a88f2458481cfe1b3c5f4ce4dc76a1cf04f210fb6cbaa106bde3f7116330d
- 44b6b1de9a618c97788631bc89372435a6ea0357e50497152a67219dea400209
- d8afcd4a1ad314c4f310a90e4f55d08155685585ac7dd03353794e493f312ce0
- 9681d73bdba27623a68e4faf1a10d928e6ca0e9fe697a378b96957c6aa46c38e
- bdbac9fe9e7aca3a03d55867eddd905c4e222f3045b0015b823df4f034ee007a
- 8b7cf22511ad2579339c7b05f513d02dd2d0d8c35f523cb79875006520f8435b
- 99d2abed5ce05b6616a33c16911038a40a7fabda7a6a4c2220daaf7ae4e6512c
- 1af6e82e53622e4404668aa00e2772aae2515110a4440721c2ece040011fe981
- afa765b692d2952cf8693c9d5b7070214e11f9f681f4b4f14142531cadaf3e92
- b3636a27cba5ba4c0c41e60c90a57a3250cbfbd1042879515cc132f74354d06e
- b218a4d70fabb2b1e986449597e4c40f9b8d10b1b5038e9e53d14534703ba8d1
Additional Informations
- Accounting
- Finance
- Retail
- Insurance
- Real Estate
- rok628.mxhelp.top
- pv-sq.innocreed.com
- 0bd0.adrsxpjm0rga0n.de
- slplegalfinance.com
- sans.infosedi.de
- administrator.pulseriseglobal.com
- advancedaiinfrastructures.com
- lory473.top
- yoc736.ikhelp.top
- subjent25.zapto.org