logo

Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools

ID: d5dc2103-8bee-50b0-bf3c-c3935680b31b

STIX ID: report--d5dc2103-8bee-50b0-bf3c-c3935680b31b

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers observed a growing campaign where cybercriminals use fake download sites mimicking popular utilities (e.g., Notepad++, 7-Zip) to deliver legitimate RMM tools (LogMeIn Resolve, PDQ Connect). Once installed, the RMM clients register with their cloud management infrastructure and attackers execute PowerShell commands through the RMM to install the PatoRAT backdoor, providing persistent remote access and enabling follow-on actions such as credential theft or ransomware; the report emphasizes detection challenges since the tools appear legitimate and recommends downloading from official sources and monitoring RMM activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.