Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools
ID: d5dc2103-8bee-50b0-bf3c-c3935680b31b
STIX ID: report--d5dc2103-8bee-50b0-bf3c-c3935680b31b
Feed Name: cybersecurityNews.com
Researchers observed a growing campaign where cybercriminals use fake download sites mimicking popular utilities (e.g., Notepad++, 7-Zip) to deliver legitimate RMM tools (LogMeIn Resolve, PDQ Connect). Once installed, the RMM clients register with their cloud management infrastructure and attackers execute PowerShell commands through the RMM to install the PatoRAT backdoor, providing persistent remote access and enabling follow-on actions such as credential theft or ransomware; the report emphasizes detection challenges since the tools appear legitimate and recommends downloading from official sources and monitoring RMM activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
