#RMMTools
Detect Black Basta Ransomware Campaign RMMTools Deployment - Social Engineering Attack via Teams where the ransomware operator sends a SharePoint link to user to download portable RMM tools to evade detection from web proxy. www.rapid7.com/blog/post/20...
December 10, 2024 at 5:35 AM
Cybercriminals are exploiting RMM tools to orchestrate multi-million dollar cargo thefts in the trucking industry. #CyberSecurity #CargoTheft #RMMTools #TruckingIndustry Link: thedailytechfeed.com/cybercrimina...
November 5, 2025 at 3:00 PM
Your RMM, our Script, and 79% off = perfect match.

🕒 Get it now: techpio.com/plugins/prod...

#MSP #RMMTools #Windows11Upgrade
Windows 11 Upgrade Script for RMM Tools | TechPIO
Windows 11 Upgrade Script for RMM tools. Compatible with ConnectWise Automate, Datto RMM, NinjaOne, SyncroMSP, and Continuum RMM. Download Now!
techpio.com
July 31, 2025 at 10:59 PM
Hackers Weaponize Trusted IT Tools for Full System Control #CyberFraud #PhishingCampaign #RMMTools
Hackers Weaponize Trusted IT Tools for Full System Control
 Malicious actors are weaponizing legitimate Remote Monitoring and Management (RMM) tools, turning trusted IT software into a means for unauthorized system access. This strategy represents a significant shift from traditional malware attacks, as it exploits programs like LogMeIn Resolve (formerly GoToResolve) and PDQ Connect to gain full remote control over a victim's computer, bypassing many conventional security measures because the software itself is not inherently malicious. Modus operandi  The core of this attack methodology lies in social engineering, where attackers trick individuals into installing these legitimate RMM applications under false pretenses. Security researchers have noted a significant increase in telemetry for detections labeled RiskWare.MisusedLegit.GoToResolve, indicating a rise in this type of threat. The attackers employ various deceptive tactics, including using misleading filenames for the installers. One common method involves sending phishing emails that appear legitimate. For instance, an email sent to a user in Portugal contained a link that, when hovered over, pointed to a file hosted on Dropbox. By using a legitimate file-hosting service like Dropbox and a trusted RMM tool, attackers increase the likelihood of bypassing security software that might otherwise flag suspicious links or attachments . In other cases, attackers set up fraudulent websites that perfectly mimic the download pages of popular free utilities like Notepad++ and 7-Zip, tricking users into downloading the malicious RMM installer instead of the software they were seeking. When a victim clicks the malicious link, it delivers an RMM installer that has been pre-configured with the attacker’s unique "CompanyId." This hardcoded identifier automatically links the victim's machine directly to the attacker’s control panel. This setup allows the attacker to instantly spot and connect to the newly compromised system without the need for stolen credentials or the deployment of additional malware . Because RMM tools are designed to run with administrative privileges, and their network traffic is often allowed by firewalls and other security solutions, the malicious remote access blends in with normal IT administrative traffic, making it extremely difficult to detect. Mitigation tips To defend against this evolving threat, it is crucial to be vigilant about the source of all software downloads . * Download carefully: Always download software directly from the official developer's website or verified sources. * Verify before installing: Check file signatures and certificates before running any installer to ensure they are from a trusted publisher. * Question unexpected prompts: If you receive an unexpected prompt to update software, verify the notification through a separate, trusted channel, such as by visiting the official website directly . * Stay updated: Keep your operating system and all installed software up to date with the latest security patches. * Recognize social engineering: Learn to identify the deceptive tricks attackers use to push malicious downloads .
dlvr.it
December 5, 2025 at 3:19 PM
Former Black Basta affiliates automate executive targeting via mass email bombing and Microsoft Teams help-desk impersonation, gaining remote access within minutes using tools like Supremo and Quick Assist. #BlackBasta #RMMTools #TechAttack
Are Former Black Basta Affiliates Automating Executive Targeting?
A refined, highly automated campaign by likely former Black Basta affiliates combines mass email bombing with Microsoft Teams help-desk impersonation to gain remote access to senior leaders within minutes, often using RMM tools like Supremo and Quick Assist. Defenders are advised to implement out-of-band verification for remote-access requests, tighten RMM allow-listing, and run targeted simulations for executives. #BlackBasta #Supremo
www.hendryadrian.com
April 15, 2026 at 2:30 AM
Cybercriminals exploit RMM tools in phishing campaigns, impersonating trusted entities to gain unauthorized access. #CyberSecurity #Phishing #RMMTools #ConnectWise #ScreenConnect #IRS #SSA thedailytechfeed.com/cybercrimina...
June 16, 2026 at 7:02 AM
Ransomware gangs are exploiting RMM tools to infiltrate networks and exfiltrate data. Learn how to protect your organization. #CyberSecurity #Ransomware #RMMTools #DataProtection Link: thedailytechfeed.com/ransomware-g...
July 23, 2025 at 4:13 PM