logo

Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors

ID: a2a04325-1b37-5410-9e65-c54e1f46bf22

STIX ID: report--a2a04325-1b37-5410-9e65-c54e1f46bf22

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign observed beginning February 2026 delivers EV-certificate-signed executables named to resemble Microsoft Teams, Zoom, Adobe Reader and related installers; when executed the payloads install RMM tooling (ScreenConnect, Tactical RMM, Mesh Agent) via encoded PowerShell and msiexec, establish persistence by copying to Program Files, registering as services and creating Run registry entries, and call back to the C2 domain trustconnectsoftware.com—allowing stealthy remote control, lateral movement, and data access. Detection is complicated by legitimate-looking digital signatures and the use of trusted RMM frameworks; recommended mitigations include blocking unapproved RMM, enforcing MFA on RMM accounts, enabling Safe Links/Safe Attachments/Zero-hour Auto Purge, application control/AppLocker rules, attack-surface reduction, and cloud-delivered endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.