Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors
ID: 8db465ad-b5ad-5d07-9418-86c331882d4e
STIX ID: report--8db465ad-b5ad-5d07-9418-86c331882d4e
Feed Name: securityonline.info
Microsoft Defender researchers uncovered a sophisticated phishing campaign that leverages familiar branding and a valid EV certificate issued to TrustConnect Software PTY LTD to sign malicious installers (masquerading as msteams.exe/adobereader.exe). Victims who run the installers receive persistent RMM backdoors (ScreenConnect, Tactical RMM, MeshAgent) that register services, create Run-key persistence, and call out to a C2 domain (trustconnectsoftware.com), illustrating a high-impact enterprise-focused supply-chain-style deception that evades user suspicion and standard warnings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
