Skip to content
Threat Actors Use Windows Screensavers To Evade Defences & Deploy Remote Control Tools

Threat Actors Use Windows Screensavers To Evade Defences & Deploy Remote Control Tools

Linkedin February 5, 2026

Cybercriminals are increasingly turning to overlooked Windows file types to bypass security controls, and a newly observed campaign shows how something as mundane as a screensaver can become a powerful malware delivery mechanism.

According to new research released by ReliaQuest , threat actors are leveraging Windows screensaver files (.scr) as part of targeted phishing campaigns to gain persistent, interactive access to corporate environments. By disguising malicious executables as harmless screensavers, attackers are exploiting a long-standing disconnect between how users perceive certain file types and how Windows actually handles them.

Despite their benign-sounding name, Windows .scr files are not configuration files or media assets. They are fully functional Portable Executable (PE) binaries , meaning they can execute arbitrary code just like .exe files. However, many security controls—and many users—do not treat them with the same level of suspicion.

Andrew Adams, a researcher at ReliaQuest, explains that this gap creates a meaningful attack surface. Screensaver files often slip past application control policies, email filtering rules, and even endpoint protections that are tightly tuned to watch for traditional executable formats.

In practical terms, this means an attacker can deliver a malicious payload in a format that:

Looks unfamiliar rather than dangerous Is less likely to be explicitly blocked by default security rules Exploits user curiosity or complacency

This technique aligns with a broader trend in modern attacks: weaponizing legitimate functionality rather than exploiting software vulnerabilities .

The attack chain observed by ReliaQuest begins with a business-themed spear phishing email , often masquerading as an invoice, project update, or internal document review request. The email contains a link to a screensaver file hosted on a consumer cloud storage platform outside the victim’s organization.

Once downloaded and executed, the .scr file installs a legitimate remote monitoring and management (RMM) agent—specifically the commercial tool JWrapper . From there, the attacker connects to the compromised system using standard RMM capabilities.

This approach offers several advantages to attackers:

No custom malware required Minimal attacker-owned infrastructure Reduced likelihood of triggering malware signatures Immediate interactive access to the victim system

Because RMM tools are widely used by IT teams, their presence may not initially raise alarms—especially in organizations without strict allowlisting policies.

Security researchers often describe these campaigns as examples of living-off-the-land techniques, where attackers abuse trusted tools and services rather than introducing obvious malware. The misuse of RMM software has become particularly common in ransomware and espionage operations over the past several years.

Once installed, the RMM tool provides attackers with:

Persistent access across reboots Full desktop interaction File transfer capabilities Command execution and system reconnaissance

From that foothold, follow-on activity may include credential harvesting, lateral movement, data exfiltration, or eventual ransomware deployment.

As Adams notes, this delivery model is highly adaptable. Attackers can easily swap:

The phishing lure The cloud hosting provider The RMM tool itself

Yet the underlying workflow remains the same, making it scalable and resilient against piecemeal defensive improvements.

While the screensaver-based delivery method may appear novel, it fits squarely within a well-established pattern. Advanced threat groups have previously abused Windows shortcut (.lnk) files, ISO images, HTML smuggling, and signed installers to achieve similar results.

In fact, ReliaQuest points out that as recently as August 2025 , attackers used .scr files to deploy the remote access trojan GodRAT against financial institutions—demonstrating that this tactic is neither theoretical nor short-lived.

The lack of attribution in the current campaign further underscores its opportunistic nature. Because attackers are relying on consumer cloud platforms and rotating outbound infrastructure, there is no consistent autonomous system number (ASN) or network signature to tie the activity to a specific threat group.

According to ReliaQuest, this strongly suggests financially motivated actors rather than a single, tightly organized advanced persistent threat (APT).

The campaign highlights several uncomfortable realities for defenders:

File type trust is often outdated Legitimate tools can be weaponized with little effort Cloud services blur traditional perimeter visibility

Many organizations focus heavily on blocking malware, but far fewer focus on controlling what legitimate software is allowed to run and why .

ReliaQuest recommends a layered response strategy focused on both technical controls and policy enforcement:

1. Treat Screensavers as Executables Security teams should explicitly classify .scr files as executables within endpoint protection and application control frameworks. Tools such as Windows Defender can restrict execution to signed or approved binaries only.

2. Strictly Control RMM Usage Organizations should maintain a clearly defined allowlist of approved RMM tools and actively alert on unauthorized agent installations. Any RMM deployment outside IT workflows should be treated as a high-severity incident.

3. Reduce Exposure to Consumer File Hosting Blocking or tightly controlling access to non-business cloud storage services at the DNS or proxy layer can significantly reduce the effectiveness of phishing campaigns that rely on external downloads.

Screensaver-based attacks are unlikely to disappear. As long as there are executable formats that fall outside the narrow definition of “dangerous” in security tooling, attackers will continue to exploit them.

This campaign serves as a reminder that modern cyber defense is less chasing malware families and more understanding how legitimate functionality can be misused . The difference between a harmless screensaver and a fully compromised system may come down to a single click—and a single overlooked file extension.

ReliaQuest is a cybersecurity company that helps large organizations detect and respond to cyber threats. Its main product, GreyMatter , uses automation and AI to unify security tools and speed up threat investigation and response. Founded in 2007 and based in Tampa, Florida, ReliaQuest focuses on making security operations more efficient for enterprise teams.

Wednesday, February 18 at 12 PM ET for Securely Yours: When IAM Meets the CISO, a Valentine's-themed webinar exploring this essential security duo.

💜 What makes this partnership work (spoiler: trust, not romance)

💜 How alignment strengthens both teams and the organization

💜 Why organizations perform best when these two move as one

This session is perfect for anyone who wants to protect their org without losing sleep, or sanity.