Multiple cybersecurity incidents have been reported involving the distribution of malware through the abuse of legitimate software and remote management tools. Attackers have exploited platforms such as LogMeIn Resolve, PDQ Connect, and the open-source SteamCleaner utility by disguising malware as legitimate installers or updates. In one case, users were tricked into downloading a malicious version of LogMeIn Resolve or PDQ Connect from websites mimicking legitimate software download pages, resulting in the installation of data-exfiltrating malware. Another campaign involved a backdoor malware signed with a valid certificate and disguised as the SteamCleaner tool, distributed via GitHub repositories and websites offering illegal software. These attacks highlight the increasing sophistication of threat actors in leveraging trusted tools to bypass security controls and gain persistent access to victim systems.
The use of legitimate signatures and remote management tools allows attackers to evade traditional security products, as these tools are often whitelisted or considered benign in enterprise environments. Security researchers emphasize the need for enhanced monitoring of remote access tool usage, validation of software sources, and the implementation of behavioral detection mechanisms to identify abnormal activity associated with these tools. The campaigns demonstrate the importance of user awareness and the risks associated with downloading software from unofficial sources, as well as the necessity for organizations to maintain strict controls over the installation and execution of remote management utilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ASEC published a separate report describing a case of malware distribution exploiting LogMeIn and PDQ Connect. No further details were provided in the reference content beyond the existence of the reported abuse case.
On November 9, 2025, ASEC disclosed technical details of the campaign, including anti-sandbox checks, PowerShell-based installation of Node.js, persistence via Windows Task Scheduler, and C2 beaconing. ASEC also warned the framework could be used to deploy additional malware such as proxyware.
ASEC observed a campaign distributing a modified SteamCleaner installer through a fake illegal-software download site that redirected victims to GitHub repositories hosting the malware. The installer was signed with a valid certificate and installed a backdoor-like capability for remote command execution.
The open-source SteamCleaner project that attackers later abused had not been updated since September 2018, establishing the baseline for the trojanized version. Attackers subsequently modified this older source code for malicious distribution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.