logo

Signed malware impersonating workplace apps deploys RMM backdoors

ID: 99249de9-1a68-5798-a110-932e140cf362

STIX ID: report--99249de9-1a68-5798-a110-932e140cf362

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

In February 2026 Microsoft Defender identified coordinated phishing campaigns that used familiar lures and EV-signed binaries (issued to TrustConnect Software PTY LTD) to install remote monitoring and management (RMM) backdoors—notably ScreenConnect, Tactical RMM, and MeshAgent—enabling persistent, covert remote access; the report provides detailed TTPs, registry/service persistence artifacts, IoCs (hashes, URLs, domains, IPs), and defensive/hunting guidance for Microsoft Defender XDR and Sentinel customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.