Attackers Weaponize Legitimate RMM Tools via Fake PDFs
ID: eba037d7-c460-5359-9b73-7623e0ac654c
STIX ID: report--eba037d7-c460-5359-9b73-7623e0ac654c
Feed Name: securityonline.info
AhnLab ASEC warns of a campaign (active since at least October 2025) that uses phishing PDFs to direct victims to download legitimate or modified, digitally signed RMM installers (Syncro, SuperOps, NinjaOne, ScreenConnect); attackers leverage these trusted remote-management tools to establish persistent, stealthy remote control, with observed NSIS-based downloaders retrieving payloads from domains such as anhemvn124.com and signing certificates tying activity to past campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
