Phishing Campaigns Exploit RMM Tools to Sustain Remote Access
ID: b07140e1-e600-57cb-8570-661bfc829a64
STIX ID: report--b07140e1-e600-57cb-8570-661bfc829a64
Feed Name: GBHackers
This report describes a sophisticated phishing campaign that distributes malicious installers disguised as legitimate browser updates, meeting invites, e‑invites, and government forms to deploy RMM tools (ITarian, PDQ Connect, SimpleHelp, Atera). Attackers use MSI sideloading and signed binaries to install remote-access agents and info-stealers (DeerStealer, HijackLoader), host payloads on Cloudflare R2, and leverage Telegram for C2/exfiltration; the report provides IOCs (domains, filenames, process/registry behaviors) and mitigation guidance including allowlisting, EDR monitoring, browser isolation, and egress filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
