logo

Threat Actors Exploit RMM Tools Through Weaponized PDF Files

ID: bb35cb9c-5334-53ef-801b-53f4afadf9ce

STIX ID: report--bb35cb9c-5334-53ef-801b-53f4afadf9ce

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

AhnLab details an active campaign (since at least October 2025) where threat actors use phishing PDFs and social engineering to trick users into installing legitimate RMM tools (Syncro, SuperOps, NinjaOne, ScreenConnect) and NSIS downloaders signed with valid certificates; attackers leverage living-off-the-land tactics to evade detection and maintain persistent access. Recommended defenses include email filtering, security training, application whitelisting, monitoring RMM installation activity, and validating vendor downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.