Attackers used convincing lookalike websites impersonating CNN, Avast, and Stremio, along with fake crypto-mining game pages, to trick Windows users into installing O&O Syspectr, a legitimate, digitally signed remote administration tool. The installers were pre-linked to attacker-controlled Syspectr accounts, giving operators remote command execution, file access, software installation, and broader system control while reducing the chance of antivirus detection because the software itself was genuine. Researchers found the CNN-, Avast-, and Stremio-themed installers shared one embedded Syspectr account ID, while the crypto-themed lure used another, suggesting either multiple operators or separate accounts used by the same group.
The activity aligns with a broader phishing trend in which threat actors abuse legitimate remote monitoring and management tools instead of custom malware. In the SeasonalInvite campaign, active since at least January, attackers used nearly 1,000 domains, poisoned search results, and fake eCard pages to deliver signed tools including ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr to Windows and macOS users. O&O Software GmbH said it suspended the abusive Syspectr accounts and disabled Remote Desktop and Remote Console for free Syspectr accounts, while researchers warned that the same traffic distribution infrastructure may be supporting multiple phishing operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On July 14, Forescout published research describing the SeasonalInvite campaign, including its use of 959 domains, a traffic distribution system, and abused signed RMM products such as O&O Syspectr.
Forescout reported that the SeasonalInvite campaign was still delivering payloads in late June 2026, showing the operation remained active for at least six months.
Microsoft documented overlapping infrastructure in March 2026 when the same operation used tax-themed lures, linking SeasonalInvite to earlier activity.
Forescout said the SeasonalInvite phishing campaign had been active since at least January 2026, using fake electronic greeting card lures to trick Windows and macOS users into installing legitimate RMM tools.
Within days of learning about the abuse, O&O Software disabled Remote Desktop and Remote Console for free Syspectr accounts, identified and suspended the abusive accounts, and blocked them from adding new devices.
The same campaign also used fake crypto-mining lure sites, including syncminer[.]xyz and idleminer[.]pro, to distribute O&O Syspectr installers tied to a different embedded Syspectr account ID.
A campaign used lookalike CNN, Avast, and Stremio websites to trick Windows users into downloading legitimate O&O Syspectr installers pre-linked to an attacker-controlled account, enabling remote access if installed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.