logo

CyberheistNews Vol 16 #04 The Skeleton Key: How Attackers Weaponize Trusted RMM Tools for Backdoor Access

ID: ba6f467e-5b98-57ca-96d7-fb13923e28aa

STIX ID: report--ba6f467e-5b98-57ca-96d7-fb13923e28aa

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-01-27

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

This CyberheistNews issue describes a two-stage campaign dubbed “The Skeleton Key” where attackers first harvest credentials through convincing Greenvelope-themed phishing and then use those credentials to generate RMM access tokens and deploy a payload ("GreenVelopeCard.exe") to turn trusted Remote Monitoring and Management tools into persistent backdoors; the newsletter also covers LinkedIn comment phishing, weaponized AI enabling large-scale scams, and reports on crypto theft and training gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.