logo

Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore 

ID: ea07287b-92a1-5244-8e80-ac828529df54

STIX ID: report--ea07287b-92a1-5244-8e80-ac828529df54

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
70/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: GridGuardGhoul

...
...

ANY.RUN observed a rise in phishing-to-RMM campaigns where threat actors use phishing pages that impersonate trusted vendors (Microsoft, Adobe, OneDrive) to trick users into installing legitimate remote-management tools (ScreenConnect, LogMeIn Rescue, Datto RMM, etc.). Because the payloads and infrastructure often appear legitimate, these campaigns create a visibility gap for SOCs — enabling unauthorized remote access, longer dwell times, and increased lateral movement risk — and require detection based on full attack-chain context (phishing lure, download context, execution behavior, RMM install, and outbound connections) rather than reputation alone.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.