N-able is a legitimate remote monitoring and management (RMM) tool that has been abused by threat actors as an initial-access and persistence payload. Proofpoint observed a fake IRS-themed phishing campaign on 05 February 2026 in which a Bitbucket URL disguised as a “Transcript Viewer” delivered an executable that installed N-able RMM; the email included a legitimate IRS phone number to increase credibility. Across tax-themed campaigns in early 2026, N-able was one of the RMM tools most commonly delivered via phishing, alongside Datto, RemotePC, Zoho Assist, and ScreenConnect. Cofense also reported that N-able was almost exclusively seen in Portuguese-language campaigns, with more than 90% of observed volume in that language set. Since at least January 2025, Proofpoint has also tracked a cybercriminal cluster targeting trucking and logistics companies that used RMM and remote access tools including N-able, ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, and LogMeIn Resolve. In those campaigns, attackers used compromised load boards, hijacked email threads, and direct phishing emails containing malicious URLs that led to .exe or .msi installers for RMM deployment. After installation, the actors used these tools to gain initial access, perform system reconnaissance, harvest credentials, maintain persistent control, and facilitate cargo theft operations affecting surface transportation entities, especially trucking carriers and freight brokers. The use of N-able in these campaigns reflects abuse of signed, legitimate administration software to evade detection rather than malware-specific functionality. No malware-family-specific IOC beyond delivery context is directly provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote monitoring and management tool abused in tax-themed phishing campaigns to gain remote access on victim hosts.
N-able is a legitimate RMM tool abused by threat actors for persistent remote access and control in targeted attacks.
Legitimate RMM tool leveraged by threat actors to establish persistent remote access to compromised systems in the transportation industry.
Remote management/remote access tooling referenced as a top family in Portuguese-language campaigns (abuse implied by context).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.