Threat reporting has highlighted phishing-led intrusions in which attackers use legitimate remote monitoring and management (RMM) software to gain and retain access to victim environments. The approach can obscure malicious activity within approved administrative tooling, creating a material visibility gap for security teams and enabling adversaries to operate without deploying obviously malicious remote-access malware.
The activity includes a U.S.-targeted phishing campaign and broader organized-cybercrime tradecraft that pair social engineering with RMM abuse. Organizations should treat unexpected RMM installation, new unattended-access configurations, and remote-control sessions initiated after phishing activity as high-priority signals; enforce application allowlisting and least privilege for RMM tools; and require strong authentication, centralized logging, and alerting for all remote-management access.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Huntress identified a second August phishing incident delivered through AT&T Office@Hand that used the same fake Adobe Reader update lure. Two unauthorized ScreenConnect instances were installed, and one session ran HideUL.exe; although Microsoft Defender detected some activity, a rogue client installed before Huntress contained the attack.
Huntress detected a phishing attack in August in which a victim was sent from a fake CAPTCHA page to a browser-in-the-browser Adobe Reader lure. The fake installer deployed two rogue ScreenConnect clients and ran HideCursor.exe before Huntress stopped the attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
itsecurityguru.org
Open sourcenetlas.io
Open sourceany.run
Open sourceany.run
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.