ANY.RUN

New Phishing-to-RMM Attacks: How Analysts Can Detect Trusted-Tool Abuse Early

ANY.RUN researchers uncovered a phishing-to-RMM campaign in which attackers use fake Microsoft, Adobe, and OneDrive pages to deliver legitimate remote management tools such as ScreenConnect and LogMeIn Rescue. 

Detection is difficult because the payload and infrastructure can look legitimate in isolation. Analysts need to connect the full chain, from phishing lure to RMM execution and outbound connections, to catch the abuse before damage is done. 

Targeted Regions and Industries

ANY.RUN data shows that phishing-to-RMM activity is most visible in the United States, followed by Canada, Europe, and Australia. 

The most affected industries include Education, Technology, Banking, Government, Manufacturing, and Finance. These sectors often rely on remote administration for IT support, distributed teams, endpoint maintenance, and user assistance, which makes RMM activity harder to judge at first glance. 

For analysts, that means triage should not stop at the tool name. A ScreenConnect or LogMeIn Rescue installer may be legitimate, but the surrounding context matters: where it was downloaded from, what page delivered it, what the user expected to receive, and which connections appeared after execution 

How the Attack Moves from Fake Page to Remote Access

ANY.RUN sandbox analyses exposed several phishing-to-RMM chains where attackers used familiar brands, misleading downloads, and legitimate remote access tools to create a path into the system. 

Case 1: Fake Microsoft Store Page Delivers ScreenConnect

The analysis session below shows a phishing page impersonating the Microsoft Store and Adobe Acrobat Reader DC. Check the recent analysis session 

A fake Microsoft Store page with an RMM installer disguised as Adobe

The user is prompted to download Adobesetup.exe, but behind that name is ScreenConnect; an RMM tool attackers can use to establish remote access to the system.  

Turn suspicious activity into clear evidence faster, so your team can validate threats, prioritize response, and avoid wasting time on uncertain alerts. Strengthen triage now 

Case 2: Fake OneDrive Download Leads to ScreenConnect

Another chain uses a protected Microsoft OneDrive download lure. The page at vmail.app.n8n.cloud shows a “Verify to Download” prompt for what appears to be a PDF document. After the click, the user receives ScreenConnect.ClientSetup.exe. 

Fake Microsoft OneDrive page with an RMM installer analyzed inside ANY.RUN sandbox

This makes triage harder because the landing page is hosted on the legitimate n8n.cloud platform, while the RMM download and connection happen through legitimate ScreenConnect infrastructure.

In cases like this, detection cannot rely on domain reputation alone. Analysts need to look at download context, execution behavior, and RMM-related connections. 

Case 3: VBS Script Installs LogMeIn Rescue

ScreenConnect is not the only tool used in these chains. ANY.RUN researchers also observed abuse of other legitimate RMM and remote-access tools, including Datto RMM, ITarian, LogMeIn Rescue, Action1 RMM, NetSupport, Syncro, MeshAgent, SimpleHelp, RustDesk, and Splashtop. 

In one analysis, the user is shown a phishing page with an Adobe document download lure. Instead of the expected file, the page delivers a VBS script. 

VBS document disguised as an Adobe Acrobat installer exposed inside ANY.RUN sandbox

Once executed, the script attempts to elevate privileges through UAC, disable SmartScreen, and weaken Microsoft Defender protections. It then silently downloads the LogMeIn Rescue installer, removes the Mark-of-the-Web, and runs a quiet installation via msiexec, leaving the endpoint with unattended RMM access. 

Turning RMM Ambiguity into Actionable Evidence

Phishing-to-RMM attacks are hard to validate with traditional detection alone because the final payload may be a legitimate remote access tool. A hash check, domain reputation lookup, or static verdict may not show the real risk.

The malicious signal appears in the chain: the phishing page, the misleading download, the execution flow, and the connection that follows. 

Behavioral analysis inside an interactive sandbox makes that chain visible. Instead of judging the RMM installer in isolation, analysts can see how it was delivered, what the user was shown, what was executed on the system, whether protections were weakened, and which remote access connections appeared after launch. 

For analysts, this means: 

  • Faster triage with clear URL-to-execution visibility
  • Stronger validation of suspicious RMM activity
  • Less time lost on “legitimate tool or attack?” uncertainty
  • Better threat hunting with behavior, network activity, and related indicators
  • Easier handoff with reports that show screenshots, process activity, network connections, and IOCs
  • Clearer escalation when RMM activity needs containment or deeper investigation

Reduce Triage Load With Earlier Threat Clarity

For teams dealing with gray-zone attacks like phishing-to-RMM, speed depends on context. Analysts need to see how the threat started, what was executed, which connections appeared, and whether a trusted tool is being abused before they can make the right call. 

Teams using ANY.RUN already reports measurable improvements across SOC workflows, including: 

  • Up to 20% decrease in Tier 1 workload
  • 30% reduction in Tier 1 to Tier 2 escalations
  • 21-minute reduction in MTTR per case
  • 94% of users report faster triage

By moving analysis to a cloud-based environment, teams can also reduce hardware setup costs, get faster threat insights, and make more informed response decisions before suspicious activity turns into a business impact. 

Gain full visibility into complex attack chains to reduce triage delays, cut unnecessary escalations, and help your team respond before threats impact the business. 

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago