Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodphishing-campaign-intelligenceremote-access-implantbotnet-infrastructure

Social-engineering campaigns abusing legitimate remote access tools (ScreenConnect and RustDesk)

Updated 2mo agoFirst seen Feb 3, 20265 sources

Two separate social-engineering campaigns are abusing legitimate remote access software to obtain interactive control of victim systems. One phishing operation uses fake party invitation emails—often appearing to come from compromised email accounts—to lure recipients to a spoofed invitation webpage that pressures them to download and run an RSVPPartyInvitationCard.msi installer. Malwarebytes researchers reported the activity primarily targeting the UK, with the MSI using msiexec.exe to silently install the ScreenConnect remote support client, enabling attackers to access files, credentials, and other sensitive data.

A different, automated campaign is targeting RustDesk users by bombarding exposed RustDesk IDs with unsolicited connection requests labeled “Go Client” from many IPs/IDs. The activity is described as not exploiting a RustDesk vulnerability; instead it relies on users mistakenly clicking Accept, after which the botnet can run scripted actions to deploy additional malware and establish persistence. Recommended mitigations include refusing unexpected connection prompts and configuring RustDesk to require a password (and strong credentials) for session acceptance, reducing the risk of one-click authorization leading to takeover.

Share:
Social-engineering campaigns abusing legitimate remote access tools (ScreenConnect and RustDesk)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 12, 20263mo ago

Spanish-language invoice campaign abuses ScreenConnect installers

By 2026-03-12, researchers documented an active campaign using Spanish- and English-language invoice lures to install legitimately signed ConnectWise ScreenConnect clients configured for attacker-controlled relays, giving persistent unattended access. The report identified live infrastructure on 80.76.49[.]161 and described an obfuscated VBS dropper that elevated privileges, downloaded the MSI, installed it silently, and removed the installer.

The ScreenConnect Epidemic: Inside a Live Spanish-Language Invoice Campaign With a Panel Still Serving Payloads - Breakglass Intelligence - Breakglass Intelligence
Feb 3, 20265mo ago

RustDesk warns users to harden remote-access settings

As the RustDesk connection-flooding campaign was reported, the RustDesk team recommended requiring passwords for incoming connections, using strong passwords, and considering self-hosting with protected server details. Additional mitigations included ACLs in the Professional self-hosted edition, 2FA, and IP whitelisting to restrict access to trusted sources.

Fake party-invitation campaign deploys ScreenConnect in the UK

A phishing campaign used fake party-invitation emails, often sent from compromised accounts, to trick recipients into downloading an MSI that silently installed the legitimate ScreenConnect remote access client. Malwarebytes reported the activity as primarily targeting users in the United Kingdom, giving attackers persistent remote control over infected Windows systems.

Jan 28, 20265mo ago

Automated botnet campaign begins targeting RustDesk IDs

In late January 2026, attackers launched an opportunistic botnet-driven campaign that scanned for active RustDesk IDs and sent unsolicited connection requests from many IP addresses and identifiers. The activity relied on social engineering rather than a software vulnerability, attempting to trick users into accepting a connection from a client labeled "Go Client."

Apr 1, 20251y ago

STAC6405 begins phishing campaign using LogMeIn Resolve and ScreenConnect

Beginning as early as April 2025, Sophos says threat cluster STAC6405 targeted more than 80 organizations across multiple U.S. sectors with phishing lures such as Punchbowl invitations and tender solicitations. The attackers delivered legitimate RMM tools, primarily LogMeIn Resolve and sometimes ScreenConnect, preconfigured for attacker-controlled remote access to establish persistent initial access.

Threat Actors Abuse LogMeIn Resolve and ScreenConnect in Multi-Stage Phishing Attacks
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
1 linked
Affected products
8 linked
ScreenconnectWindowsWindows InstallerPowershellAdobe ReaderOnedriveRemote Desktop Protocol (Rdp)Microsoft Defender
Organizations
14 linked
ConnectwiseDigiCertMozillaMalwarebytesSamsung ElectronicsZoom CommunicationsWordpressAppleMicrosoft CorporationGoogleBreakglass IntelligenceVirtuo NetworksFranTechOVH US
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.