Skip to content
Block-Continue
Go back

The Party Invite That Wasn't: Anatomy of a ScreenConnect Phishing Campaign

The Hook

It arrived like dozens of other emails do every week: a friendly, informal invitation to a get-together. The subject line read something like “Dear Friends & Family, join me for a joyful gathering…” It sounded warm, personal, unremarkable. It came from someone real. Someone in the recipient’s contact list. Someone they had exchanged email with before.

That’s what made it work.

Over the past several months, our institution, like a growing number of others in higher education and beyond, has been targeted by a phishing campaign that doesn’t rely on urgency, fear, or fake invoices. It relies on something much harder to defend against: borrowed trust.

How the Attack Works

The mechanics are simple, which is exactly why they’re effective.

  1. An email account gets compromised. It doesn’t matter whose: a friend, a colleague, a family member. Once an attacker has access to someone’s real inbox and contact list, they have a delivery mechanism that no spam filter is going to flag as suspicious. The sender address is legitimate. The signature looks right. The relationship is real.

  2. A party invitation goes out to everyone in that contact list. The invite is polished, casual, and socially framed: a “get-together,” a birthday party, a “special occasion.” It asks the recipient to click through to see details and RSVP.

  3. The RSVP link leads to a fake invitation page, hosted on attacker-controlled infrastructure, that prompts a file download disguised as the invitation itself.

  4. The downloaded file is not an invitation. It’s an installer for ScreenConnect, a legitimate, widely used remote support tool that IT teams rely on every day. In the hands of an attacker, it grants full remote access to the victim’s machine: screen viewing, keyboard and mouse control, and file access, all under the guise of software nobody thinks twice about because it’s the same category of tool their own help desk might use.

  5. The compromise propagates. If the victim’s email account gets compromised in the process, the cycle repeats: their contacts receive the same invitation, from what looks like a completely trustworthy source, and the campaign spreads laterally through social graphs rather than through a traditional spray-and-pray email blast.

This isn’t a hypothetical. Security researchers and multiple institutions, including other universities, have documented functionally identical campaigns since early 2026, and our own incident response teams identified and responded to several real compromises tied to this exact pattern.

Why This One Is Different

Most phishing awareness training focuses on spotting red flags: mismatched sender domains, urgent language, suspicious links, poor grammar. This campaign sidesteps nearly all of that.

That single inconsistency was, in every case we investigated, the only tell available before the click.

What We Found

Our incident response process combined several layers of visibility (email gateway logs, endpoint detection, and network traffic analysis) to trace the campaign from initial phishing emails through to individual compromised devices. That layered approach mattered: no single control caught everything on its own, but together they let us map the full scope of the campaign rather than treating each infected device as an isolated event.

A few findings worth sharing:

What We Did About It

For every confirmed compromise, our response followed a consistent playbook:

What This Means for You

You don’t need to work in higher ed IT for this to be relevant. This exact pattern (compromised account, personal-sounding invite, malicious “RSVP” download) has been reported hitting individuals, businesses, and other organizations well outside our sector.

A few practical takeaways:

Social engineering campaigns like this one succeed by exploiting something fundamentally human: our willingness to trust the people we know. That’s not a vulnerability you patch with software. It’s one you address by teaching people to pause, just for a moment, before an invitation asks them to do anything more than say yes.


This writeup describes an incident at a large institution. All internal IPs have been substituted with RFC 1918 ranges and identifying details have been generalized.


Share this post on:

Next Post
The Store That Wasn't There