Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore
ID: ea07287b-92a1-5244-8e80-ac828529df54
STIX ID: report--ea07287b-92a1-5244-8e80-ac828529df54
Feed Name: ANY.RUN's Cybersecurity Blog
ANY.RUN observed a rise in phishing-to-RMM campaigns where threat actors use phishing pages that impersonate trusted vendors (Microsoft, Adobe, OneDrive) to trick users into installing legitimate remote-management tools (ScreenConnect, LogMeIn Rescue, Datto RMM, etc.). Because the payloads and infrastructure often appear legitimate, these campaigns create a visibility gap for SOCs — enabling unauthorized remote access, longer dwell times, and increased lateral movement risk — and require detection based on full attack-chain context (phishing lure, download context, execution behavior, RMM install, and outbound connections) rather than reputation alone.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
