Signed malware impersonating workplace apps deploys RMM backdoors
ID: 99249de9-1a68-5798-a110-932e140cf362
STIX ID: report--99249de9-1a68-5798-a110-932e140cf362
Feed Name: Microsoft Security
Date Published: 2026-03-03
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
In February 2026 Microsoft Defender identified coordinated phishing campaigns that used familiar lures and EV-signed binaries (issued to TrustConnect Software PTY LTD) to install remote monitoring and management (RMM) backdoors—notably ScreenConnect, Tactical RMM, and MeshAgent—enabling persistent, covert remote access; the report provides detailed TTPs, registry/service persistence artifacts, IoCs (hashes, URLs, domains, IPs), and defensive/hunting guidance for Microsoft Defender XDR and Sentinel customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
