Skip to main content

RMM Tools Being Distributed Through Phishing Attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

0
Medium
Published: 10/08/2026 (10/08/2026, 07:10:37 UTC)
Source: AlienVault OTX General

Description

Threat actors are distributing legitimate Remote Monitoring and Management (RMM) tools such as ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able through phishing campaigns. These campaigns use social engineering tactics with fake Adobe Acrobat updates, DocuSign viewers, and document access prompts to trick victims into installing remote access tools disguised as business documents. Delivery methods include LNK files, BAT scripts, VBS files, and PDFs. The RMM tools contain embedded configuration data linking back to attacker infrastructure, enabling remote access while evading detection.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 08:18:22 UTC

Technical Analysis

Multiple Remote Monitoring and Management (RMM) tools are weaponized and distributed via phishing campaigns involving video files and email attachments. Threat actors exploit legitimate IT administration tools like ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able to gain remote access to compromised systems. The campaigns employ social engineering lures such as fake Adobe Acrobat updates and DocuSign viewers to convince victims to install these tools. The installation files include configuration data with deployment IDs, account identifiers, and command-and-control server addresses controlled by attackers. Delivery vectors include LNK, BAT, VBS files, and PDFs disguised as business documents, facilitating stealthy remote access and evasion of security detection.

Potential Impact

Successful phishing leads to installation of legitimate RMM tools configured for attacker control, granting remote access to compromised systems. This enables threat actors to evade security detection by abusing trusted IT administration software. The embedded configuration data allows persistent command-and-control communication, potentially facilitating further malicious activities on affected systems.

Defensive Guidance

No official patch or fix applies as this is an abuse of legitimate software rather than a software vulnerability. Mitigation focuses on user awareness to recognize phishing lures and avoid executing suspicious attachments or links. Organizations should monitor for unauthorized use of RMM tools and validate the legitimacy of remote access software installations. Employing email filtering and endpoint protection to detect phishing and malicious scripts can reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://asec.ahnlab.com/ko/95750/"]
Adversary
Scattered Spider
Pulse Id
6ac741ed2968234538d416fa

Indicators of Compromise

Domain

ValueDescriptionCopy
domainalertxen.store
—
domainbigsundoc.online
—
domainddncsoso.com
—
domainhessattorneys.co.za
—
domainrelay.lukiku.lol
—
domainadmin.lukiku.lol
—

Hash

ValueDescriptionCopy
hash1017a75cf19be75f6ba21148a9b646d1
—
hash1562d523c2ebdc19c0ff8f3ea5f3763b
—
hash594a652263e5e4eb96b5164d337bc1ca
—
hash5a49d0b22ced22f9cf8b2015a327f163
—
hash5ac7526b582d9cf4f7854c52ee75f359
—
hashfccc77bb369c41a410be97bf306cfb55380cc063
—
hash015755b2fdb66633f6f9dac2a473f0806a1c094f33d963687538fce90cf7ed90
—

Ip

ValueDescriptionCopy
ip216.250.252.58
—

Threat ID: 6ac74e5f2cdf04f656fcc26d

Added to database: 10/08/2026, 08:03:43 UTC

Last enriched: 10/08/2026, 08:18:22 UTC

Last updated: 10/08/2026, 18:48:07 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses