Huntress SOC analysts detail recurring social engineering tactics used by threat actors in 2025 to deploy rogue ScreenConnect RMM installations. Common lures include fake Social Security statements, event invitations, and overdue invoices disguised as executables. The post provides concrete IoCs including top malicious domains, SHA256 hashes, and executable naming patterns observed across multiple victim organizations. ScreenConnect accounts for 74.5% of abused remote access tools seen by Huntress. Mitigation recommendations include security awareness training, RMM auditing, log review, and Managed EDR solutions.
Table of contents
Common tactics used in attacksTop domains and hashesTotal occurrences across different accountsA ScreenConnect attack: As seen in the SOCPutting RMMs on lockdown2 Impressions