Crims create fake remote management vendor that actually sells a RAT
ID: 625a46f7-fb46-5b53-a7fa-1aa12a7a6087
STIX ID: report--625a46f7-fb46-5b53-a7fa-1aa12a7a6087
Feed Name: The Register (Security)
Proofpoint uncovered a RAT-as-a-service (TrustConnect) masquerading as legitimate RMM software that used a fake vendor website and a now-revoked EV code-signing certificate to sign malware, enabling it to bypass defenses; the RAT provides full remote control (screen recording/streaming, file transfer, command execution) and was distributed via phishing campaigns (e.g., MsTeams.exe → TrustConnectAgent.exe) with C2 infrastructure (178.128.69.245) that was briefly disrupted before operators pivoted to new infrastructure and a rebranded agent (DocConnect/SHIELD OS v1.0).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
