logo

RMM Tools (Syncro, SuperOps, NinjaOne, etc.) Being Distributed Disguised as Video Files

ID: 5c0fedcd-9913-59f7-87b2-0f0c2d4f44af

STIX ID: report--5c0fedcd-9913-59f7-87b2-0f0c2d4f44af

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-26

Author: ATCP

...
...

ASEC observed a phishing campaign using malicious PDF lure documents that redirect victims to counterfeit Google Drive/Adobe pages to download signed RMM installers (Syncro, ScreenConnect, NinjaOne, SuperOps). Installers and NSIS downloaders are signed with a certificate tied to recurring activity since October 2025; the report provides configuration details (keys/customer IDs), MD5 hashes, and malicious URLs as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.