Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access

A novel dual-vector campaign that uses credentials that have been obtained to install authentic Remote Monitoring and Management (RMM) software for ongoing remote access to vulnerable computers has been revealed by cybersecurity researchers.

According to researchers Jeewan Singh Jalal, Prabhakaran Ravichandhiran, and Anand Bodke of KnowBe4 Threat Labs, “attackers are circumventing security perimeters by weaponizing the essential IT tools that administrators trust, rather than deploying custom viruses.” “By stealing a ‘skeleton key’ to the system, they turn legitimate Remote Monitoring and Management (RMM) software into a persistent backdoor.”

Threat actors use phony invitation notifications to obtain victim credentials, which they then use to deploy RMM tools to create persistent access. The attack takes place in two separate waves.

The fraudulent emails pose as invitations from Greenvelope, a reputable platform, with the intention of tricking recipients into clicking on a phishing UR read more about Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *