logo

Distribution of Malware Abusing LogMeIn and PDQ Connect

ID: 09c9dcb8-848b-5b63-b749-9c8ff468d8ae

STIX ID: report--09c9dcb8-848b-5b63-b749-9c8ff468d8ae

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-11-09

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC identified attacks in which threat actors used fake download pages to distribute installers for LogMeIn Resolve and PDQ Connect that register attacker-controlled CompanyId values; those RMM tools were then used to execute PowerShell and install PatoRAT, a Delphi backdoor with remote control, HVNC, keylogging and credential-theft capabilities. The report documents PatoRAT's 1-byte XOR RC_DATA "APPCONFIG" format, sample clientTags, supported commands, observed CompanyId values, MD5 hashes, malicious URLs/FQDNs, and advises validating download sources, certificates, and keeping systems and security products updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.