RMM Tools Being Distributed Through Phishing Attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)
Description
Threat actors are distributing legitimate Remote Monitoring and Management (RMM) tools such as ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able through phishing campaigns. These campaigns use social engineering tactics with fake Adobe Acrobat updates, DocuSign viewers, and document access prompts to trick victims into installing remote access tools disguised as business documents. Delivery methods include LNK files, BAT scripts, VBS files, and PDFs. The RMM tools contain embedded configuration data linking back to attacker infrastructure, enabling remote access while evading detection.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Multiple Remote Monitoring and Management (RMM) tools are weaponized and distributed via phishing campaigns involving video files and email attachments. Threat actors exploit legitimate IT administration tools like ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able to gain remote access to compromised systems. The campaigns employ social engineering lures such as fake Adobe Acrobat updates and DocuSign viewers to convince victims to install these tools. The installation files include configuration data with deployment IDs, account identifiers, and command-and-control server addresses controlled by attackers. Delivery vectors include LNK, BAT, VBS files, and PDFs disguised as business documents, facilitating stealthy remote access and evasion of security detection.
Potential Impact
Successful phishing leads to installation of legitimate RMM tools configured for attacker control, granting remote access to compromised systems. This enables threat actors to evade security detection by abusing trusted IT administration software. The embedded configuration data allows persistent command-and-control communication, potentially facilitating further malicious activities on affected systems.
Defensive Guidance
No official patch or fix applies as this is an abuse of legitimate software rather than a software vulnerability. Mitigation focuses on user awareness to recognize phishing lures and avoid executing suspicious attachments or links. Organizations should monitor for unauthorized use of RMM tools and validate the legitimacy of remote access software installations. Employing email filtering and endpoint protection to detect phishing and malicious scripts can reduce risk.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/ko/95750/"]
- Adversary
- Scattered Spider
- Pulse Id
- 6ac741ed2968234538d416fa
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainalertxen.store | — | |
domainbigsundoc.online | — | |
domainddncsoso.com | — | |
domainhessattorneys.co.za | — | |
domainrelay.lukiku.lol | — | |
domainadmin.lukiku.lol | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash1017a75cf19be75f6ba21148a9b646d1 | — | |
hash1562d523c2ebdc19c0ff8f3ea5f3763b | — | |
hash594a652263e5e4eb96b5164d337bc1ca | — | |
hash5a49d0b22ced22f9cf8b2015a327f163 | — | |
hash5ac7526b582d9cf4f7854c52ee75f359 | — | |
hashfccc77bb369c41a410be97bf306cfb55380cc063 | — | |
hash015755b2fdb66633f6f9dac2a473f0806a1c094f33d963687538fce90cf7ed90 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip216.250.252.58 | — |
Threat ID: 6ac74e5f2cdf04f656fcc26d
Added to database: 10/08/2026, 08:03:43 UTC
Last enriched: 10/08/2026, 08:18:22 UTC
Last updated: 10/08/2026, 18:48:07 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.