Detect Phishing-to-RMM Trusted Tool Abuse
ANY.RUN researchers uncovered a phishing-to-RMM campaign in which attackers use fake Microsoft, Adobe, and OneDrive pages to deliver legitimate remote management tools such as ScreenConnect and LogMeIn Rescue.
Detection is difficult because the payload and infrastructure can look legitimate in isolation. Analysts need to connect the full chain, from phishing lure to RMM execution and outbound connections, to catch the abuse before damage is done.
ANY.RUN data shows that phishing-to-RMM activity is most visible in the United States, followed by Canada, Europe, and Australia.
The most affected industries include Education, Technology, Banking, Government, Manufacturing, and Finance. These sectors often rely on remote administration for IT support, distributed teams, endpoint maintenance, and user assistance, which makes RMM activity harder to judge at first glance.
For analysts, that means triage should not stop at the tool name. A ScreenConnect or LogMeIn Rescue installer may be legitimate, but the surrounding context matters: where it was downloaded from, what page delivered it, what the user expected to receive, and which connections appeared after execution
ANY.RUN sandbox analyses exposed several phishing-to-RMM chains where attackers used familiar brands, misleading downloads, and legitimate remote access tools to create a path into the system.
The analysis session below shows a phishing page impersonating the Microsoft Store and Adobe Acrobat Reader DC. Check the recent analysis session
The user is prompted to download Adobesetup.exe, but behind that name is ScreenConnect; an RMM tool attackers can use to establish remote access to the system.
Turn suspicious activity into clear evidence faster, so your team can validate threats, prioritize response, and avoid wasting time on uncertain alerts. Strengthen triage now
Another chain uses a protected Microsoft OneDrive download lure. The page at vmail.app.n8n.cloud shows a “Verify to Download” prompt for what appears to be a PDF document. After the click, the user receives ScreenConnect.ClientSetup.exe.
This makes triage harder because the landing page is hosted on the legitimate n8n.cloud platform, while the RMM download and connection happen through legitimate ScreenConnect infrastructure.
In cases like this, detection cannot rely on domain reputation alone. Analysts need to look at download context, execution behavior, and RMM-related connections.
ScreenConnect is not the only tool used in these chains. ANY.RUN researchers also observed abuse of other legitimate RMM and remote-access tools, including Datto RMM, ITarian, LogMeIn Rescue, Action1 RMM, NetSupport, Syncro, MeshAgent, SimpleHelp, RustDesk, and Splashtop.
In one analysis, the user is shown a phishing page with an Adobe document download lure. Instead of the expected file, the page delivers a VBS script.
Once executed, the script attempts to elevate privileges through UAC, disable SmartScreen, and weaken Microsoft Defender protections. It then silently downloads the LogMeIn Rescue installer, removes the Mark-of-the-Web, and runs a quiet installation via msiexec, leaving the endpoint with unattended RMM access.
Phishing-to-RMM attacks are hard to validate with traditional detection alone because the final payload may be a legitimate remote access tool. A hash check, domain reputation lookup, or static verdict may not show the real risk.
The malicious signal appears in the chain: the phishing page, the misleading download, the execution flow, and the connection that follows.
Behavioral analysis inside an interactive sandbox makes that chain visible. Instead of judging the RMM installer in isolation, analysts can see how it was delivered, what the user was shown, what was executed on the system, whether protections were weakened, and which remote access connections appeared after launch.
For analysts, this means:
For teams dealing with gray-zone attacks like phishing-to-RMM, speed depends on context. Analysts need to see how the threat started, what was executed, which connections appeared, and whether a trusted tool is being abused before they can make the right call.
Teams using ANY.RUN already reports measurable improvements across SOC workflows, including:
By moving analysis to a cloud-based environment, teams can also reduce hardware setup costs, get faster threat insights, and make more informed response decisions before suspicious activity turns into a business impact.
Gain full visibility into complex attack chains to reduce triage delays, cut unnecessary escalations, and help your team respond before threats impact the business.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…