logo

Freight Hacker Wields Code-Signing Service to Evade Defenses

ID: 552d63b3-0618-58c0-a9ee-8064bec7a5c1

STIX ID: report--552d63b3-0618-58c0-a9ee-8064bec7a5c1

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

...
...

Proofpoint researchers uncovered a financially motivated cybercriminal group targeting freight and logistics companies via phishing that delivers VBS and PowerShell payloads to install RMM tools (SimpleHelp, Pulseway, ConnectWise ScreenConnect) for remote control, credential theft and cargo diversion. The actors notably used a third-party code-signing service to fraudulently sign ScreenConnect installers (domains observed: amtechcomputers.net, signer.bulbcentral.com) to evade defenses, and deployed multiple scripts to enumerate accounts, collect browsing/banking data, and exfiltrate to attacker-controlled Telegram bots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.