logo

Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors

ID: 8db465ad-b5ad-5d07-9418-86c331882d4e

STIX ID: report--8db465ad-b5ad-5d07-9418-86c331882d4e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender researchers uncovered a sophisticated phishing campaign that leverages familiar branding and a valid EV certificate issued to TrustConnect Software PTY LTD to sign malicious installers (masquerading as msteams.exe/adobereader.exe). Victims who run the installers receive persistent RMM backdoors (ScreenConnect, Tactical RMM, MeshAgent) that register services, create Run-key persistence, and call out to a C2 domain (trustconnectsoftware.com), illustrating a high-impact enterprise-focused supply-chain-style deception that evades user suspicion and standard warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.