logo

Incident responders, s'il vous plait: Invites lead to odd malware events

ID: d3e22e60-c4db-59a9-892b-066e38b05ccd

STIX ID: report--d3e22e60-c4db-59a9-892b-066e38b05ccd

Feed Name: Sophos Blogs

Threat Score
70/100

Date Published: 2026-03-30

Date Updated: 2026-04-30

...
...

Sophos MDR observed a phishing campaign (tracked as STAC6405) that tricks recipients into installing legitimate RMM tools (LogMeIn Resolve / ScreenConnect) preconfigured to give attackers unattended access; in a subset of cases the actors subsequently delivered and executed additional malicious payloads (an infostealer packed with HeartCrypt and a Java-based RAT/remote access payload). The campaign affected over 80 organizations (mostly US), used multiple attacker-controlled domains and at least one C2 IP (45.56.162.138), leveraged living-off-the-land techniques and delayed-execution/LOLBIN injection to evade detection, and shows indicators of ongoing activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.