logo

Don’t trust TrustConnect: This fake remote support tool only helps hackers

ID: 85c72b12-17f3-5fa9-95c9-ab6a54ea829e

STIX ID: report--85c72b12-17f3-5fa9-95c9-ab6a54ea829e

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-28

...
...

The report describes an active campaign in which adversaries delivered signed, faux installers impersonating common applications (Zoom, Teams, Adobe Reader, Google Meet) via email; these installers deploy a remote access trojan (TrustConnect) that automatically registers infected hosts to the operator's control panel. The TrustConnect site functions as both a legitimate-seeming marketing front and a backend portal for customers of the malicious service, and campaign lures and timeline activity (including ScreenConnect and LogMeIn Resolve lures) are noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.