logo

Multi-RMM attack: Splashtop Streamer and Atera payloads delivered via Discord CDN link · Blog · Sublime Security

ID: b68ce5c7-1456-5eaa-ad88-1ad2fe6f7528

STIX ID: report--b68ce5c7-1456-5eaa-ad88-1ad2fe6f7528

Feed Name: Sublime Security Blog

Threat Score
70/100

Date Published: 2025-11-13

Date Updated: 2026-05-01

...
...

This Attack Spotlight describes an email-based campaign where a compromised Microsoft 365 account and OneDrive impersonation were used to trick recipients into downloading a file whose extension was manipulated (.docx → .msi). The installer deployed two RMM tools (Atera and Splashtop), downloaded from legitimate sources and Discord CDN, giving attackers persistent remote access; Sublime's detection engine intercepted the attack before further payload or ransom activity was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.