logo

Signed malware posing as Teams and Zoom apps drops RMM backdoors

ID: 3608833e-5850-54ab-87ca-381b292af99b

STIX ID: report--3608833e-5850-54ab-87ca-381b292af99b

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A campaign observed by Microsoft Defender used convincing phishing emails and spoofed download pages to distribute EV-signed binaries impersonating Microsoft Teams, Zoom, and Adobe Reader; executing these installers deployed multiple RMM backdoors (ScreenConnect, Tactical RMM, MeshAgent) that established persistent Windows services, Run keys, and outbound C2 communication to domains such as trustconnectsoftware.com — the report includes filenames, registry/service artifacts, and mitigation guidance including AppLocker/WDAC, MFA for RMM, Defender hunting, and certificate-blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.