Infosecurity

Fake eCards Are Installing Legit Remote Access Tools: What You Need to Know

Published

on

Holiday Greetings, Malicious Payloads

That Valentine’s Day eCard from a “friend” might not be a token of affection. It could be a carefully crafted trap.

Security researchers at Forescout have uncovered a six-month phishing operation that abuses electronic greeting cards to sneak legitimate remote monitoring and management (RMM) software onto Windows and macOS devices. The campaign, dubbed SeasonalInvite, has been active since at least January 2026 and was still serving payloads in late June.

This isn’t your run-of-the-mill malware drop. The attackers are using validly signed, commercially available tools — the same software IT teams use for remote support. That’s what makes this so insidious.

How the SeasonalInvite Phishing Campaign Works

The attack chain is deceptively simple. The operators rotate their lures to match the calendar. In winter, it was tax and Social Security themes. By spring, Valentine’s Day, Easter, and other seasonal invitations took over.

The researchers identified 959 domains used in phishing emails and poisoned search results. But here’s the twist: not everyone who clicks gets the payload. A traffic distribution system (TDS) screens each visitor before redirecting them to a page impersonating the greeting card service BlueMountain.

If you pass the screening, you see a loading animation. Three seconds later, an installer downloads automatically — tailored to your operating system. No interaction needed beyond the initial click.

Windows and macOS: Two Paths, Same Goal

On Windows, the attack relies on batch and VBScript droppers. They fetch the installer and then relaunch themselves to trigger a User Account Control (UAC) prompt. The victim is asked to approve the privileged install — a clever social engineering move that makes the process feel legitimate.

The macOS variant is even more sophisticated. It splits delivery into two parts: a signed Kaseya package and a separate config.data file. That file redirects enrollment to the attacker’s server, abusing an unattended-deployment feature built for managed service providers.

Legitimate RMM Tools, Attacker Control

Four commercially signed RMM products were abused in this campaign:

Because these installers are genuine and validly signed, they slip past security checks that would normally flag malware. The victim’s own system is essentially helping the attacker gain access.

Each landing page also quietly harvested the visitor’s IP address, city, and browser type, posting that data to a backend. The operator kept a record of everyone who reached the page — a goldmine for future targeting.

AI-Assembled Phishing Kit

Forescout’s analysis found indicators that the phishing pages were assembled with help from a large language model (LLM). Emoji-prefixed task comments and references to combining a “first snippet” and “second snippet” are telltale signs.

The operator likely used an AI tool to stitch together code for operating-system detection, Telegram-based reporting, and animation logic. This lowers the cost of producing fresh variants — a worrying trend for defenders.

The TDS itself appears to be a larger, shared platform. A search for pages matching its gate-page fingerprint returned 2,658 URLs. Many looked benign to automated scanners but quietly routed real users onward. Not all carried the SeasonalInvite fingerprint, suggesting the system may serve several unrelated phishing operations at once.

Microsoft separately documented overlapping infrastructure in March, when the same operation leaned on tax-themed lures. This is a persistent, evolving threat.

How to Protect Against eCard Phishing

Forescout urges organizations to take a proactive stance:

  • Maintain an approved inventory of RMM tools and alert on any others that appear.
  • Harden email filtering against seasonal themes — these lures change with the calendar.
  • Train staff that a genuine eCard should never require installing remote support software or approving an elevation prompt.

For individuals, the advice is simpler: be skeptical of unexpected eCards, especially those that ask you to download anything. If a greeting card requires software installation to view, it’s not a greeting — it’s a threat.

This campaign is a stark reminder that the line between legitimate tools and malicious use is razor-thin. The same software that helps IT teams fix your laptop can be turned against you in seconds.

Stay alert. That digital Valentine might not have your best interests at heart.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version