logo

Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures

ID: c48f8fb7-da72-5cc6-86df-2e75d982156d

STIX ID: report--c48f8fb7-da72-5cc6-86df-2e75d982156d

Feed Name: Netskope Threat Labs

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-28

Author: Jan Michael Alcantara

...
...

Netskope Threat Labs is tracking active phishing campaigns that use fake video conference invites and "mandatory" update prompts to trick users into installing digitally signed RMM tools (Datto RMM, LogMeIn, ScreenConnect). By leveraging legitimate, signed remote monitoring and management agents, attackers gain persistent administrative access to endpoints, enabling sensitive data exfiltration, lateral movement, and large-scale malware or ransomware deployment across corporate environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.