Threat Actors Exploit RMM Tools Through Weaponized PDF Files
ID: bb35cb9c-5334-53ef-801b-53f4afadf9ce
STIX ID: report--bb35cb9c-5334-53ef-801b-53f4afadf9ce
Feed Name: GBHackers
AhnLab details an active campaign (since at least October 2025) where threat actors use phishing PDFs and social engineering to trick users into installing legitimate RMM tools (Syncro, SuperOps, NinjaOne, ScreenConnect) and NSIS downloaders signed with valid certificates; attackers leverage living-off-the-land tactics to evade detection and maintain persistent access. Recommended defenses include email filtering, security training, application whitelisting, monitoring RMM installation activity, and validating vendor downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
