logo

CAMO Unveiled: How Cybercriminals Exploit Legitimate Software for Stealthy Attacks

ID: 9bf64e00-dd0b-5177-b92d-50392d911c7b

STIX ID: report--9bf64e00-dd0b-5177-b92d-50392d911c7b

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2024-09-05

Date Updated: 2026-04-29

...
...

This ReliaQuest report defines and documents the growing trend of CAMO (abuse of legitimate commercial applications for malicious operations), showing that attackers increasingly adopt legitimate IT tools—such as PDQ Deploy, AnyDesk, ScreenConnect, SoftPerfect, and Restic—to evade detection and achieve ransomware deployment, lateral movement, discovery, and data exfiltration; it presents multiple case studies (Medusa, Inc Ransom, Black Basta), forum activity demonstrating tool sharing and cracking, and recommended mitigations including baselining, application whitelisting, network segmentation, cloud controls, and allowlisting of authorized RMM tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.