different species of crabsoft-shell crab
3
8 Comments

How a simple Downloads organizer is being used to stop ScreenConnect scams

I created Mouzi (https://github.com/hsr88/mouzi) because my "Downloads" folder looked like a digital dumping ground. The app has grown significantly since then, but I never expected anyone to use it as protection against remote access scams. And yet - it's probably the most interesting use case I've heard of so far.

Last week, I received an email from Peter. Peter fixes computers for everyday people - the ones who call in a panic when something stops working and they have no idea why. He wrote to me saying he uses Mouzi to fight scams. This surprised me, because how? After all, Mouzi is meant for sorting files.

It turned out that Peter is using the software to protect his clients from "ScreenConnect" scams. The scenario usually goes like this: the victim answers the phone, hears a friendly voice talking about a "virus," and - following instructions - downloads a remote access tool sent by the fake "support."

I’ve watched enough Scammer Payback on YouTube to know what a plague this is abroad (the scale is probably smaller here in Poland, though it’s still an issue). The worst part is that ScreenConnect is completely legitimate software used by IT departments worldwide. That's exactly why antivirus programs don't block it, and the victim only has to click once for the scammer to gain remote access to the computer - to banking, files, everything. Peter was looking for something that would intercept this file in a split second, the moment it's downloaded, before anyone could even run it.

And this is where Mouzi steps in. Peter wrote a single rule: if a downloaded file has "screenconnect" in its name, move it immediately to a safe location. Not after a scan, not after a warning - the file disappears from the Downloads folder before the victim even looks at it. Peter claims the program is fast enough to preempt a click from an unsuspecting person. After solving a few technical difficulties and exchanging some emails, he successfully implemented the tool into his workflow. Now, every single one of his clients will have Mouzi installed as their first line of defense.

By the way, a funny thing came up here, because one of Peter's main issues at the beginning was... bad naming in the interface. At one point he wrote: "I think I got it! Your 'Edit' button really means Save!!!!!". Well, lesson learned - time for some UX tweaks!

Thanks to Peter's email, I now have a few new ideas for Mouzi's development. He threw in some concrete suggestions: a "safe trash" option or simpler name matching. Instead of just complex regular expressions (regex), I'll add an option for simple phrase typing (e.g., "file name contains..."). This will make Mouzi accessible to everyone, not just advanced users.

Thank you to Peter for the support, brilliant feedback, and new ideas.

P.S. Yes, Peter agreed to let me write about this case.

P.P.S. Yes, in the next update, I will change the "Edit" button to "Save"!

posted to Icon for group Building in Public
Building in Public
on July 27, 2026
  1. 1

    peter emailing you is the alarm going off. the interesting part is he only found you AFTER hed already reverse-engineered mouzi into a scam blocker. how many peters are out there right now doing the same thing without emailing?

    the compounding move isnt just packaging peters rule as a preset (which ryan called out). its turning his rule into a shareable public artifact: screenshot of the rule + a "heres what mouzi actually caught this week" line on x/ih/linkedin. presets solve for users who already know mouzi. rule-posts pull in the users who dont. would peter let you run that as a monthly "field report" series?

  2. 2

    Peter's use case feels less like a reason to pivot and more like a reason to package a preset. I'd keep file organization at the center, then add a one-click "block known remote access installers" recipe with plain-language matching and a safe restore path. That turns the surprising workflow into something nontechnical users can use without exposing them to regex. The Edit/Save confusion points the same way. This audience needs recipes and reversible actions more than extra power.

    1. 1

      That’s exactly right, I think I’ll go down that route

  3. 2

    This was a really practical breakdown. I knew about ScreenConnect scams, but I never thought a simple Downloads organizer could help reduce the risk. Thanks for sharing your workflow.

    1. 1

      Exactly, I wouldn’t have expected that Mouzi could be used for that either - thanks as well :)

  4. 2

    The interesting part is how an existing utility found a completely different security use case through a real user.

    Curious whether this scam-prevention workflow changes your roadmap, or if you still see file organization as the core product?

    1. 1

      I’d say it’s changed a lot in my roadmap. I no longer see Mouzi as just a tool for organising files, and my future plans are… well, huge ;) We’ll see how it turns out

      1. 1

        That's a pretty interesting evolution. I'd enjoy hearing how your thinking develops as you explore it. What's the best email to reach you on?

Trending on Indie Hackers
Stop losing deals in the gap between "sounds good" and getting paid User Avatar 64 comments Building a startup costs $0. Your tooling budget costs $500K. Here's why. User Avatar 50 comments We scanned 50,000 domains. Your cold email list is really four systems. User Avatar 39 comments 787 tools for developers. 5 for nurses. Two weeks of tracking 14,000 indie launches. User Avatar 38 comments 67K impressions in 2 days from a single Daily-Dev post — here's what happened User Avatar 24 comments 🚀 I built Brickbeam — an AI-powered assistant that helps LEGO fans turn their messy piles of bricks into real builds. User Avatar 21 comments