Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: rmm-abuse (3 articles)Clear

Global phishing campaign tricks victims into installing legitimate remote-control software

Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.

Check
Maintain an inventory and allowlist of approved remote-management tools, block or alert on any others, and warn staff that finance and government-themed messages may push legitimate remote-access software.
Affected
Organizations and users targeted by business-themed phishing that delivers legitimate remote monitoring and management tools; once installed, attackers gain hands-on remote access that looks like ordinary IT activity and evades reputation-based defenses.
Fix
Allowlist approved remote-access software and disable the rest, require remote access through controlled paths like VPNs, monitor for unexpected remote-management execution, and detect on the stable delivery chain rather than disposable domains.

Anubis ransomware hides in legitimate remote-management tools after breaching via Citrix

Arctic Wolf detailed how affiliates of the Anubis ransomware group break in and stay hidden, drawing on intrusions across healthcare, finance, and manufacturing this year. Initial access came from stolen VPN credentials and from exploiting CitrixBleed 2, a NetScaler flaw that leaks session tokens from memory and lets attackers bypass multi-factor authentication. Once inside, the affiliates leaned on legitimate remote-management software such as ScreenConnect, Zoho Assist, and MeshAgent to blend in with normal IT activity, moving through networks with RDP and PsExec toward domain controllers, backups, and storage devices. They stole data using common cloud-transfer tools before encrypting anything, which is exactly where defenders have the best chance to catch them.

Check
Patch NetScaler against CitrixBleed 2 and terminate all active sessions afterward, then audit your environment for remote-management tools like ScreenConnect, Zoho Assist, or MeshAgent that IT did not deploy.
Affected
Organizations running unpatched Citrix NetScaler Gateways or reusable VPN credentials; Anubis affiliates use these to get in, then hide inside legitimate remote-management tools while stealing data ahead of encryption.
Fix
Patch CitrixBleed 2 and kill existing sessions, enforce phishing-resistant MFA on VPNs, allowlist approved remote-management tools and alert on any others, and watch for RMM installs and exfiltration tools clustering together.

Phishing campaign hit 80+ companies by getting employees to install legitimate remote-access software disguised as a Social Security letter

Securonix tracked a phishing campaign called VENOMOUS#HELPER that has hit 80+ organizations (mostly in the US) since April 2025 by getting employees to install legitimate remote-monitoring software they think is a Social Security Administration document. The lure is a fake SSA email asking the recipient to download their statement; the link points to a compromised Mexican business website hosting a SimpleHelp installer. Once installed, the attackers gain SYSTEM-level access, then quietly install ConnectWise ScreenConnect as a backup channel. The pattern aligns with initial-access broker activity: quiet persistence, then sale or hand-off to ransomware operators.

Check
Hunt every Windows endpoint for SimpleHelp and ConnectWise ScreenConnect installs not authorized by IT. Search proxy logs for connections to gruta.com.mx since April 2025.
Affected
Windows endpoints in organizations without strict application allowlisting. 80+ confirmed victims, mostly US, across multiple sectors. Acute risk: companies whose staff regularly receive government correspondence (SSA, IRS, state tax) where 'verify and download' lures feel routine. Initial access brokers run these campaigns to sell footholds, so any compromised host becomes a potential ransomware launchpad weeks later.
Fix
Enforce application allowlisting on Windows endpoints to block unapproved RMM software. Remove unauthorized SimpleHelp, ScreenConnect, PDQ Connect, LogMeIn Resolve, N-able, or Fleetdeck installs and treat the host as compromised. Block Securonix's published indicators (gruta.com.mx, server.cubatiendaalimentos.com.mx) at the network egress layer. Rotate credentials on affected hosts.