Signed malware posing as Teams and Zoom apps drops RMM backdoors
ID: 3608833e-5850-54ab-87ca-381b292af99b
STIX ID: report--3608833e-5850-54ab-87ca-381b292af99b
Feed Name: GBHackers
A campaign observed by Microsoft Defender used convincing phishing emails and spoofed download pages to distribute EV-signed binaries impersonating Microsoft Teams, Zoom, and Adobe Reader; executing these installers deployed multiple RMM backdoors (ScreenConnect, Tactical RMM, MeshAgent) that established persistent Windows services, Run keys, and outbound C2 communication to domains such as trustconnectsoftware.com — the report includes filenames, registry/service artifacts, and mitigation guidance including AppLocker/WDAC, MFA for RMM, Defender hunting, and certificate-blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
