logo

Weaponizing Apathy: How Threat Actors Exploit Vulnerabilities and Legitimate Software

ID: cfe811da-017e-5462-a5fb-416d36d783cd

STIX ID: report--cfe811da-017e-5462-a5fb-416d36d783cd

Feed Name: Cofense Blog

Threat Score
68/100

Date Published: 2026-04-22

Date Updated: 2026-04-27

Author: Cofense

...
...

**Executive Summary:** This Cofense analysis (Dec 2021–Dec 2024) documents the widespread abuse of legitimate software and known CVEs to deliver Remote Access Tools and other malware, highlighting Microsoft Office CVE exploitation and declining but notable use of Office macros, and enumerating prominent abused RATs (NetSupport Manager, ConnectWise, FleetDeck, Atera) used by threat actors to achieve remote control, data access, and lateral movement; the report recommends improving visibility into legitimate software abuse and prioritizing timely patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.