02 8987 4501  ·  0406 340 856
Google Reviews
Cyber Security

The "shared a file with you" email that spreads itself.

Published 8 August 2026

It arrives from someone you actually deal with, because their account is already compromised. Click the link, run the file, and your computer joins the chain. Then it goes out to everyone in your address book.

Why IT Service Centre
Since 2004Two decades supporting Sydney businesses
2-hour responseDuring business hours, sooner for urgent issues
One partnerSupport, security, networks and cloud, together

What the email looks like

The subject is some variation of "invited you to view a folder" or "shared a file with you". There is no dodgy grammar and no unfamiliar sender. It comes from a real business you correspond with, because the attacker is sitting inside that person's mailbox and can see how they normally write.

The body is deliberately mundane. One we were shown recently read: "I'm trying to get more organized in making our data for different things more shared/visible." Vague enough to fit almost any working relationship, specific enough to sound like a person. Underneath sits a generic folder icon, an Open button, and a line reassuring you the invite only works for you and people with existing access.

That is the whole trick. Every instinct staff are trained on, checking the sender, looking for odd phrasing, being wary of strangers, gives the right answer here. The sender is genuine. The account has just stopped belonging to its owner.

The line that gives it away

There is one tell in that message worth knowing, because it appears again and again: "For security reasons, please view the file on your desktop or windows laptop."

Read as a security instruction it sounds responsible. It is the opposite. The payload only runs on Windows, so the attacker needs you off your phone and onto a machine they can actually infect. Anyone opening it on an iPhone would see nothing happen and might get suspicious. A legitimate file share does not care what device you are on.

If an email tells you which device to open something on, that is not caution. That is the attacker choosing their ground.

What happens if someone clicks

The link leads to a download rather than a document. The file prompts to install what is usually ScreenConnect, a legitimate remote support tool that IT providers use every day. It is properly signed, widely deployed, and does not look like malware to most security software, which is exactly why it was chosen.

Once it runs, whoever is on the other end has the same access a technician would: the file system, saved credentials, anything the logged-in user can reach. Recent versions of this attack install the agent under a name like "Windows Security" and configure it so it cannot easily be viewed or removed, even by an administrator.

Then it does the same thing again

This is the part worth understanding, and the reason it spreads the way it does. With mailbox access, the attacker harvests the contact list and sends the same file-share email onward, from the real account, into real conversation threads.

On one machine we rebuilt, the harvesting was not even improvised. Sitting in ScreenConnect's own file-transfer folder was a purpose-built application called "Email Extractor Outlook", pushed down the remote session and run against the local Outlook profile. The address book was the objective, not an afterthought.

Every recipient then sees a message from a business they trust. Some of them click. Their contacts receive it from them. Security vendors reporting on these campaigns describe attackers studying communication patterns first and targeting the people most likely to act, which is why the messages so often land on someone in accounts or reception rather than at random.

For a clinic or a professional practice, the damage is not only technical. Your suppliers, referrers and clients receive malicious email carrying your name on it.

What it actually looks like on the machine

A few details from that rebuild, because they are worth recognising:

There was more than one. At least two separate ScreenConnect clients, each with its own identifier, installed roughly a minute apart. Removing one would have left the other running, and there is no guarantee two was the whole of it. Redundant access is deliberate, and it is a documented pattern in these campaigns.

Killing the process does nothing. End it in Task Manager and it restarts on its own, within seconds. It is running as a Windows service, so the service control manager simply starts it again. Anyone trying to deal with this through Task Manager will conclude their computer is possessed, and give up.

It installs like real software. Both sat in Program Files alongside genuine applications, with proper file structures and signed components. Nothing about a folder listing looks wrong.

It has to be stopped as a service. Setting the service to Disabled and stopping it was the only thing that held. There was no clean uninstall, and newer variants go further, disguising the service name and locking permissions so an administrator cannot remove it at all.

The machine had mapped drives. It was a reception workstation with access to shared storage. Whoever was on the other end had that access too. There was no encryption in this case, which was luck rather than restraint, and the machine was rebuilt from scratch rather than cleaned.

That last point is the one to sit with. The compromised computer is rarely the target. It is the route to everything it can reach.

What actually stops it

It is worth being precise here, because the obvious answer is the wrong one. Multi-factor authentication does not stop this. Nobody logs into the mailbox. The attacker is already on the machine, inside an Outlook session that is open and authenticated, operating as the person sitting at that desk. No login happens, so no second factor is ever asked for. MFA is still worth having for other reasons, but it would not have prevented what happened here.

Stop the install. This is the one that matters. The entire chain depends on a user being able to run an installer. Take that away and the click leads nowhere. Standard user accounts without local administrator rights, and application control that only permits approved software to execute, are what break this attack.

Block or alert on remote access tools. ScreenConnect, AnyDesk, TeamViewer and similar are legitimate software, which is exactly why they are used. If they are not part of your environment, they should be blocked outright. If they are, you should know immediately when a new instance appears that nobody deployed.

Limit what the machine can reach. The reception workstation had mapped drives to shared storage, so the attacker inherited that access. Access should follow the job, not the convenience of having everything mapped everywhere.

Tell staff the two specific tells. A file-share link from a familiar contact is worth a phone call before it is worth a click. And any message instructing you which device to open it on should be treated as hostile until proven otherwise.

If a message like this has already been clicked on one of your machines, disconnect it from the network and call us before doing anything else. Do not assume one removal has finished the job, and do not trust a machine that has been cleaned rather than rebuilt. The priority is working out what that computer could reach, because the machine itself is rarely the point.

Had one of these arrive?

Let's check your mailboxes and devices.

A short review covers who can install software, whether any remote access tools are running that shouldn't be, and what your front-desk machines can actually reach.

Start a conversation