Spam Campaign Distributes Fake PDFs, Deploys Remote Monitoring Tools for Ongoing Access
ID: 3406349e-4dec-5dc5-8bd5-18891b9092b8
STIX ID: report--3406349e-4dec-5dc5-8bd5-18891b9092b8
Feed Name: GBHackers
Threat Score
A widespread spam campaign delivers PDF attachments that redirect victims to spoofed Adobe download pages which automatically serve genuine RMM installers (TrustConnect and Datto RMM). By leveraging signed, legitimate remote-management tools, actors establish persistent backdoors, evade AV/EDR, and can escalate privileges or deploy further payloads; the report includes IOCs (phishing URLs and SHA-256 hashes) and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
