news.mlab.sh
Back to the feed
threat-intel

More RMM Tools In the Wild, (Tue, Oct 6th)

Info
Image: SANS Internet Storm Center
Summary

Threat actors are abusing the Action1 RMM tool to deliver malicious payloads. The attack begins with a phishing email containing a fake PDF invoice that redirects to a VBS file. This VBS file then downloads and installs an MSI archive containing files associated with the Action1 RMM tool, which installs itself as a service for persistence. The files are signed with an Action1 Corporation certificate. The threat actors are leveraging Action1's cloud infrastructure.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.