logo

Attackers Hijack Trusted RMM Tools to Create Invisible, Permanent Backdoors

ID: 0d29feb0-6a1d-529a-a2ef-b274275e3e2b

STIX ID: report--0d29feb0-6a1d-529a-a2ef-b274275e3e2b

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

A sophisticated phishing campaign has been active since at least April 2025 and has impacted over 80 organizations (primarily in the U.S.) by deploying vendor-signed Remote Monitoring and Management tools to maintain stealthy, persistent access. Attackers install two independent RMMs (self-hosted SimpleHelp 5.0.1 and a ScreenConnect relay) to create redundant, self-healing remote access, persist through Safe Mode via registry hive modifications, continuously exfiltrate security posture data, and evade detection by renaming system binaries and leveraging legitimate signed software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.