Screensaver (.SCR) Files Used as Initial Access Vector
Screensaver (.SCR) Files Used as Initial Access Vector (TL-2026-0104) is a high-severity phishing campaign, first published 2026-02-16. It is attributed to Cobalt Group with high confidence, maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1036.002), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-0104
- Threat ID
- TL-2026-0104
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-02-16
- Last reviewed
- 2026-02-16
- Attribution
- Cobalt Group
- Attribution confidence
- HIGH
- Motivation
- ESPIONAGE|FINANCIAL|DESTRUCTION
- Target sectors
- Government, Defense, Diplomatic, Financial Services, Energy, Technology, Healthcare
- Target regions
- Global, Europe, North America, Asia Pacific, Middle East
- Detection rules
- 9
- Indicators of compromise
- 25
Screensaver (.SCR) files as initial access vector — Windows PE executables disguised with document/image icons, exploiting hidden extension defaults and email gateway filter gaps to achieve phishing-based code execution across APT and cybercrime campaigns since at least 2014.
How Screensaver (.SCR) Files Used as Initial Access Vector works
Windows Screensaver (.SCR) files are fully functional Portable Executable (PE) binaries that Windows treats identically to .exe files — they execute directly when double-clicked. The .scr extension is a legacy artifact of Windows screensaver functionality, but the OS makes no distinction between .scr and .exe at the execution layer. This creates a powerful initial access vector: .scr files bypass email gateway filters that block .exe but allow .scr through allowlists or oversight, Windows hides the .scr extension by default (same 'Hide extensions for known file types' behavior as .exe), and attackers use double-extension tricks (e.g., 'invoice.pdf.scr') to make malicious executables appear as documents or images.
The technique has been documented across multiple threat actor categories:
1. **Cobalt Group (Carbanak)** — Confirmed by MITRE ATT&CK (T1566.001) and PT Security (2017). Cobalt Group sent spearphishing emails with password-protected archives containing .exe and .scr executables targeting financial institutions globally. This is the highest-confidence documented use of .scr in APT spearphishing.
2. **APT29/Cozy Bear/Midnight Blizzard** — The Dukes have employed PE-based executables with icon manipulation and hidden extensions in phishing campaigns targeting diplomatic organizations. ESET documented Operation Ghost (2013-2019) using sophisticated multi-stage delivery with PE payloads. APT29's recent campaigns (2022+, documented by Mandiant/Google) use ISO/IMG containers with LNK files pointing to malicious DLLs — the evolution beyond standalone .scr to container-based delivery that bypasses MotW.
3. **Kimsuky (North Korea)** — AhnLab ASEC documented Kimsuky's evolution from HWP documents to LNK-based delivery via archives. Kimsuky uses spearphishing with compressed files containing malicious executables (including .scr-class PE files) disguised as legitimate documents, primarily targeting South Korean government and defense sectors.
4. **Gamaredon/Armageddon (Russia/FSB)** — CERT-UA documented Gamaredon using HTM, HTA, and LNK files disguised as Word/Excel documents, along with USB propagation. Their rapid attack model (data exfiltration within 30-50 minutes) leverages disguised executables.
5. **General cybercrime** — MITRE ATT&CK T1036.007 (Double File Extension) explicitly lists .scr alongside .exe, .lnk, and .hta as dangerous extensions used in double-extension masquerading. SOCPrime documented detection rules for double-extension abuse in spearphishing.
The .scr vector persists because: - Windows default settings hide file extensions, making 'document.pdf.scr' display as 'document.pdf' - .scr files execute with full PE privileges — identical to .exe - Some email gateways and web filters still don't block .scr in their executable extension lists - Archives (ZIP/RAR/7z) strip MotW from contained files on many configurations - The .scr extension has low awareness among end users compared to .exe - Modern evolution: ISO/IMG containers further bypass MotW (APT29 technique, documented by Mandiant 2022)
Mark of the Web (MotW) behavior: .scr files downloaded directly from the internet receive MotW Zone.Identifier ADS, triggering SmartScreen prompts on Windows 10+. However, when delivered inside ZIP archives (and especially ISO/IMG containers), MotW propagation is inconsistent — Windows propagates MotW into ZIP contents since Win10 but ISO/IMG mounted files do NOT carry MotW (documented by Didier Stevens 2017, confirmed by Mandiant APT29 research). This gap is what drove the evolution from .scr-in-ZIP to .scr-in-ISO delivery.
MITRE ATT&CK techniques used in TL-2026-0104
collection
T1005 Data from Local System; T1056.001 Keylogging; T1113 Screen Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036.002 Right-to-Left Override; T1036.005 Match Legitimate Resource Name or Location; T1036.007 Double File Extension; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1218.011 Rundll32
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File; T1569.002 Service Execution
command-and-control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer
defense-impairment
T1112 Modify Registry; T1553.005 Mark-of-the-Web Bypass
privilege-escalation
persistence
T1547.001 Registry Run Keys / Startup Folder
initial-access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Remediation for Screensaver (.SCR) Files Used as Initial Access Vector
Patches
- N/A — .scr execution is Windows by-design behavior, not a vulnerability
Immediate actions
- Block .scr file attachments at email gateway level — add to executable extension blocklist alongside .exe, .com, .bat, .cmd, .pif, .vbs, .js, .hta
- Disable 'Hide extensions for known file types' via GPO across all endpoints
- Configure Windows Defender SmartScreen to block unrecognized executables
- Block .scr execution from user-writable directories (%TEMP%, %APPDATA%, Downloads) via AppLocker/WDAC
Workarounds
- Rename .scr to .scr.blocked in email quarantine systems
- Configure email gateway to strip archives containing .scr files
- Deploy browser extension blocking .scr downloads
Longer-term hardening
- Deploy application whitelisting (AppLocker/WDAC) to prevent execution of unsigned .scr files
- Implement email attachment sandboxing that detonates .scr files before delivery
- Block ISO/IMG mounting by non-admin users via GPO (prevents MotW bypass)
- Security awareness training: educate users about double-extension attacks and .scr file risks
- Deploy Sysmon with process creation logging to detect .scr execution from unexpected paths
- Monitor for Alternate Data Stream Zone.Identifier removal (MotW stripping)
Timeline of Screensaver (.SCR) Files Used as Initial Access Vector
- Cobalt Group (Carbanak) begins using .scr files in spearphishing emails targeting financial institutions. PT Security documents password-protected archives containing .exe and .scr executables. Source: https://www.ptsecurity.com/upload/corporate/ww-en/analytics/Cobalt-2017-eng.pdf
- F-Secure publishes 'The Dukes' whitepaper documenting APT29 PE-based phishing with icon manipulation and extension hiding, including screensaver-class executables in spearphishing against diplomatic targets. Source: https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf
- Didier Stevens documents that files inside mounted ISO images do NOT carry Zone.Identifier (MotW) ADS — establishing the technical basis for ISO-based MotW bypass that supersedes direct .scr delivery. Source: https://blog.didierstevens.com/2017/07/18/iso-files-with-zone-identifier/
- ESET publishes Operation Ghost research showing APT29 (The Dukes) using multi-stage PE delivery with custom encryption, icon manipulation, and steganography against European Ministries of Foreign Affairs (2013-2019). Source: https://www.welivesecurity.com/2019/10/17/operation-ghost-dukes-never-left/
- SOCPrime publishes Sigma rule for detecting double-extension abuse in spearphishing, specifically calling out .scr alongside .exe as dangerous extensions hidden by Windows default settings. Source: https://socprime.com/blog/rule-of-the-week-possible-malicious-file-double-extension/
- Mandiant/Google documents APT29 evolving to ISO/IMG container delivery (ROOTSAW/EnvyScout) that bypasses MotW — the technical successor to direct .scr attachment delivery. Files inside ISO don't carry MotW, enabling execution without SmartScreen prompts. Source: https://cloud.google.com/blog/topics/threat-intelligence/tracking-apt29-phishing-campaigns/
- CERT-UA documents Gamaredon using disguised executables (HTM/HTA/LNK) with 30-50 minute data exfiltration timeline. Gamaredon plants up to 120 malicious infected files per week for persistence. Source: https://cert.gov.ua/article/5160737
- AhnLab ASEC documents Kimsuky evolving from HWP documents to LNK-based delivery inside archives, using AutoIt-compiled scripts exceeding 100MB to evade analysis. PE executable disguise remains core technique. Source: https://asec.ahnlab.com/en/59590/
- MITRE ATT&CK publishes T1036.007 (Double File Extension) explicitly listing .scr as a dangerous extension used in masquerading: 'Executable extensions commonly regarded as dangerous, such as .exe, .lnk, .hta, and .scr, often appear as the second extension.' Source: https://attack.mitre.org/techniques/T1036/007/
- DFIR Report documents LockBit ransomware attack chain beginning with PE executable masquerading as Windows Media Configuration Utility (setup_wm.exe) — demonstrating ongoing PE masquerading as standard phishing initial access for ransomware. Source: https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/
- As of 2026-05-29, this .SCR initial-access technique is intensifying, not waning: ReliaQuest (Feb 2026) tracked active .scr-via-cloud-link campaigns deploying SimpleHelp RMM, and the April 2026 DigiCert breach used a ZIP'd .scr to steal 60 EV certs signing Zhong Stealer. It is by-design Windows behavior (no CVE/patch); MITRE T1036.007 remains live, so ACTIVE holds.
Sources cited for Screensaver (.SCR) Files Used as Initial Access Vector
- MITRE ATT&CK T1036.007 — Masquerading: Double File Extension
- MITRE ATT&CK T1566.001 — Spearphishing Attachment
- MITRE ATT&CK T1204.002 — User Execution: Malicious File
- MITRE ATT&CK T1546.002 — Event Triggered Execution: Screensaver
- PT Security — Cobalt 2017: Attacks on Financial Institutions (.scr in archives)
- ESET — Operation Ghost: The Dukes (APT29) Never Left
- Mandiant/Google — Tracking APT29 Phishing Campaigns (ISO delivery evolution)
- AhnLab ASEC — Kimsuky Group Uses AutoIt to Create Malware
- CERT-UA — Gamaredon Attack Traits and Rapid Data Exfiltration
- DFIR Report — Cobalt Strike and SOCKS Lead to LockBit (PE masquerading)
- SOCPrime — Possible Malicious File Double Extension Detection
- F-Secure — The Dukes: 7 Years of Russian Cyberespionage
More in phishing
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
- Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach
- Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams
Detection coverage for TL-2026-0104
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0104 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.