Attackers are increasingly leveraging legitimate IT tools and browser features to gain unauthorized access to victims' systems and steal credentials. Recent campaigns have exploited Remote Monitoring and Management (RMM) software such as LogMeIn Resolve (GoToResolve) and PDQ Connect, tricking users into installing these trusted applications under false pretenses. Once installed, these tools provide attackers with full remote access, often bypassing traditional security controls due to their legitimate nature. Attackers distribute these installers through convincing phishing emails and fake websites that mimic popular utility download pages, using legitimate domains like Dropbox to evade detection. The attackers pre-configure the RMM tools with their own identifiers, allowing seamless control over compromised systems.
In parallel, social engineering attacks are evolving to exploit browser features and cloned websites. The ClickFix attack, for example, uses fake ChatGPT Atlas browser installers distributed via cloned sites and sponsored search results to deliver password-stealing malware. Similarly, the Matrix Push C2 platform abuses browser push notifications as a fileless attack vector, tricking users into enabling notifications that deliver fake system alerts and redirect to malicious sites. These techniques rely on the inherent trust users place in familiar brands and browser features, making them highly effective at bypassing both technical and human defenses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers at BlackFog identified a criminal platform called Matrix Push C2 that uses browser push notifications as a fileless, browser-native social-engineering and command-and-control mechanism. The framework sends fake alerts and redirects users to malware delivery or credential-harvesting pages across desktop and mobile devices.
Researchers reported that government-backed hacking groups linked to Iran, North Korea, and Russia were using the ClickFix method. The campaigns targeted services including student platforms, remote access tools, conferencing services, and AI-related browser tools.
ClickFix attacks expanded through cloned websites and fake installers, including lures such as a fake ChatGPT Atlas browser, to persuade users to paste obfuscated commands into a terminal. The technique was reported as having surged sharply and was being used to deploy password-stealing malware and escalate privileges.
A wave of attacks emerged in which threat actors trick users into installing legitimate remote monitoring and management tools such as LogMeIn Resolve (GoToResolve) and PDQ Connect, often via phishing or fake software pages. Once installed with attacker-controlled configuration, the tools provide stealthy remote access while blending in with normal IT activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcehackread.com
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.