Threat Actors Exploit LogMeIn Resolve, ScreenConnect in Phishing Campaigns
ID: 9ca47adb-9e94-54f0-84bc-4604ce758f4e
STIX ID: report--9ca47adb-9e94-54f0-84bc-4604ce758f4e
Feed Name: GBHackers
Threat Score
Sophos documents an ongoing phishing campaign (STAC6405) that lures victims with invite‑themed messages to install preconfigured LogMeIn Resolve or ScreenConnect installers, granting attackers persistent remote access; in follow‑up activity attackers have delivered an info‑stealer (HeartCrypt-packed payloads), used living‑off‑the‑land tactics and legitimate RMM/remote‑access software to harvest credentials and access crypto wallets, affecting 80+ organizations primarily in the US.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
