CAMO Unveiled: How Cybercriminals Exploit Legitimate Software for Stealthy Attacks
ID: 9bf64e00-dd0b-5177-b92d-50392d911c7b
STIX ID: report--9bf64e00-dd0b-5177-b92d-50392d911c7b
Feed Name: ReliaQuest Blog
This ReliaQuest report defines and documents the growing trend of CAMO (abuse of legitimate commercial applications for malicious operations), showing that attackers increasingly adopt legitimate IT tools—such as PDQ Deploy, AnyDesk, ScreenConnect, SoftPerfect, and Restic—to evade detection and achieve ransomware deployment, lateral movement, discovery, and data exfiltration; it presents multiple case studies (Medusa, Inc Ransom, Black Basta), forum activity demonstrating tool sharing and cracking, and recommended mitigations including baselining, application whitelisting, network segmentation, cloud controls, and allowlisting of authorized RMM tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
