A phishing campaign called SeasonalInvite, documented by the security firm Forescout, reveals a dangerous trend for small businesses: the lure is no longer an “infected” file, but a friendly email. An e-card or invitation, with themes that change according to the calendar, directs you to a page that automatically downloads an installation file after a few seconds.
That file isn’t a classic virus. It installs a real, digitally signed remote administration program—the kind legitimately used by IT companies—but it’s preconfigured to connect to the attacker’s infrastructure. Because the program is legitimate, antivirus software doesn’t block it, and whoever controls it gains full access to the computer: files, saved passwords, and open sessions.
The good news is that security doesn't depend on an expensive tool, but on a simple rule that all employees follow:
- Don't install any remote access software just because an email, a greeting card, or a call "from support" asked you to.
- If a web page automatically downloads an installation file, close the page without running the file.
- Only install software that you have initiated yourself and that you have verified with your IT department.
For a company without an in-house IT department, the simplest step is to determine in advance who approves installations and to block any remote access programs that you do not officially use.
The analyses on which the article is based:
- Forescout (Vedere Labs) | https://www.forescout.com/blog/seasonalinvite-new-phishing-campaign-abuses-ecards-and-rmm/
- Infosecurity Magazine | https://www.infosecurity-magazine.com/news/seasonalinvite-phishing-ecards-rmm/
This article was generated with AI assistance.