Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Phishing campaign uses e-cards to trick users into installing remote management software

The "SeasonalInvite" phishing campaign delivers fake e-cards that automatically download legitimate, signed remote management software (RMM) installers like ConnectWise ScreenConnect and Kaseya, which bypass standard security checks and require user approval for privileged installation. The article does not describe a specific software vulnerability with a CVSS score or fixed version; the threat exploits the trusted nature of these tools. Recommended mitigations include maintaining an approved RMM inventory, enhancing email filtering, and training staff to recognize that legitimate e-cards should never prompt for remote software installation or privilege elevation.
Read Full Article →

Phishing Phishing campaign uses e-cards to trick users into installing remote management software July 16, 2026 Share By SC Staff As reported by Infosecurity Magazine, a six-month phishing operation dubbed SeasonalInvite has been targeting Windows and macOS users by abusing remote monitoring and management (RMM) software, delivered through fake electronic greeting cards (eCards). The campaign, active since at least January 2026, employs rotating lures tied to the calendar, such as tax themes in winter and Valentine's or Easter invitations later on, according to Forescout. Victims are directed through a traffic distribution system to a fake eCard service that automatically downloads an operating-system-specific installer. This operation abuses commercially signed RMM tools like ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr. Because these installers are legitimate and validly signed, they bypass standard security checks. On Windows, the process involves UAC prompts requiring user approval for privileged installation. For macOS, a signed Kaseya package is paired with a separate configuration file to redirect enrollment to the attacker's server, exploiting an unattended deployment feature. The phishing pages show signs of AI generation, suggesting the use of large language models to create variants efficiently. Forescout recommends organizations maintain an approved inventory of RMM tools, enhance email filtering, and train staff to recognize that genuine e-cards should never prompt for remote support software installation or approval of privilege elevation. Source: Infosecurity Magazine SC Staff Related Phishing 5 charged in UK investigation into Russian Coms scam platform SC Staff July 14, 2026 The platform, active since 2020, allowed criminals to make over 1.8 million scam calls globally, targeting approximately 170,000 victims and causing tens of millions in financial losses. AI/ML Your phishing defense was built for 2016, but attackers are operating in 2026 Rod Schultz July 14, 2026 AI phishing kits outpace manual takedowns, forcing defenders to rethink strategy. Phishing AI tool ScamBuster aims to turn the tables on email scammers SC Staff July 13, 2026 ScamBuster operates by responding to incoming phishing emails with an AI-driven persona designed to appear as a gullible victim, such as an elderly individual or a novice business owner. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article