logo

The Skeleton Key: How Attackers Weaponize Trusted RMM Tools for Backdoor Access

ID: 2cd3cb59-fbaa-52c2-8928-40886af3f140

STIX ID: report--2cd3cb59-fbaa-52c2-8928-40886af3f140

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Labs documents a two-wave attack: initial credential harvesting through convincing Greenvelope-themed phishing landing pages, followed by weaponization of stolen credentials to deploy legitimately signed RMM software (GreenVelopeCard.exe) that configures GoTo Resolve/LogMeIn for silent, unattended remote control. The report provides extracted JSON deployment configuration, describes SYSTEM-level privilege escalation via service and COM API abuse, lists C2 domains, and recommends hunting for IOCs, blocking C2 domains, and monitoring for unauthorized RMM usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.