Phishing Campaign Uses Fake Party Invites to Deliver Remote Access Tools
ID: b87e328a-1e98-51b6-a8e9-a0b8718d2763
STIX ID: report--b87e328a-1e98-51b6-a8e9-a0b8718d2763
Feed Name: KnowBe4 Blog
Threat Score
A Symantec analysis details a highly active phishing campaign that uses party-themed and other lures (invoices, meeting invites, tax notices) to convince victims to install legitimate remote management and monitoring (RMM) software. Attackers rotate and chain installations of RMM tools (ScreenConnect, LogMeIn Resolve, Naverisk) to evade detection and maintain long-term access; researchers suspect the group may be selling access to other criminals such as ransomware gangs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
