Threat Actors Abuse LogMeIn Resolve and ScreenConnect in Multi-Stage Phishing Attacks
ID: 3b9aa50e-b369-52a0-87b1-98080cde703c
STIX ID: report--3b9aa50e-b369-52a0-87b1-98080cde703c
Feed Name: cybersecurityNews.com
A US-focused phishing campaign (tracked as STAC6405) distributed preconfigured legitimate LogMeIn Resolve installers via themed landing pages and compromised/impersonated senders to register victim machines to attacker-controlled accounts, impacting over 80 organizations; in some incidents ScreenConnect was abused to deploy a ValleyRAT-like infostealer and concealment utilities, enabling credential, session token, and cryptocurrency wallet theft. Recommendations include restricting software installations to an approved list, removing or blocking unauthorized RMM tools, enforcing strong credential hygiene, and promptly blocking related URLs and IoCs across network entry points.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
