{"id":5920,"date":"2025-08-06T10:06:32","date_gmt":"2025-08-06T10:06:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/06\/threat-actors-weaponizing-rmm-tools-to-take-control-of-the-machine-and-steal-data\/"},"modified":"2025-08-06T10:06:32","modified_gmt":"2025-08-06T10:06:32","slug":"threat-actors-weaponizing-rmm-tools-to-take-control-of-the-machine-and-steal-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/06\/threat-actors-weaponizing-rmm-tools-to-take-control-of-the-machine-and-steal-data\/","title":{"rendered":"Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data"},"content":{"rendered":"<p>    Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are increasingly exploiting Remote Monitoring and Management (RMM) software to gain unauthorized access to corporate systems, with a sophisticated new attack campaign demonstrating how legitimate IT tools can become powerful weapons in the wrong hands.<\/p>\n<p>This emerging threat leverages the inherent trust placed in <a href=\"https:\/\/cybersecuritynews.com\/seedworm-hackers-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">RMM solutions<\/a>, transforming essential administrative software into conduits for data theft and potential ransomware deployment.<\/p>\n<p>The latest attack campaign employs a dual-RMM strategy that significantly enhances attacker persistence and control.<\/p>\n<p>By deploying both Atera and Splashtop Streamer simultaneously, threat actors ensure continued access even if one RMM tool is discovered and removed by security teams.<\/p>\n<p>This redundancy represents a concerning evolution in attack methodology, where cybercriminals prioritize maintaining long-term access over stealth.<\/p>\n<p>The attack begins with a carefully crafted <a href=\"https:\/\/cybersecuritynews.com\/hr-it-related-phishing-emails-are-top-clicked\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing email<\/a> sent from compromised Microsoft 365 accounts to undisclosed recipient lists.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhBXk6zZ0Bkhb1mt1Eqm0KJFYnc2ZDvuFGOQ8k0jBkxxH0S_gz8R0GG8Sp1H0-ijT01PxgNVx4hhVp9psJg0-srrT1nUBq6-ABIlPNPOEaU981FdYyaivWPoso7ZeAO_8ukbzEGwp2xqkE6w31GRvnQAj1dmsO9XGxs0WdFh6_uvLOr5BvcdNhL1AesLtA\/s16000\/Malicious%2520email%2520with%2520malicious%2520attachments%2520%28Source%2520-%2520Sublime%2520Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Malicious email with malicious attachments (Source \u2013 Sublime Security)<\/figcaption><\/figure>\n<\/div>\n<p>These messages impersonate Microsoft OneDrive notifications, complete with authentic-looking Word document icons and privacy footers to establish legitimacy.<\/p>\n<p>The emails contain malicious links hosted on Discord\u2019s Content Delivery Network (cdn.discordapp.com), exploiting the platform\u2019s reputation as a trusted service to bypass initial security filters.<\/p>\n<p>Sublime Security researchers <a href=\"https:\/\/sublime.security\/blog\/multi-rmm-attack-splashtop-streamer-and-atera-payloads-delivered-via-discord-cdn-link\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign through their AI-powered detection engine, which flagged multiple suspicious indicators including file extension manipulation and OneDrive impersonation tactics.<\/p>\n<p>The researchers noted that the attack represents a significant escalation in RMM abuse, particularly due to its multi-tool approach and sophisticated social engineering components.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-payload-deployment\"><strong>Infection Mechanism and Payload Deployment<\/strong><\/h2>\n<p>The attack\u2019s infection mechanism demonstrates advanced evasion techniques through file extension manipulation.<\/p>\n<p>Victims receive links to what appears to be a <code>.docx<\/code> document but actually downloads a file named <code>Scan_Document_xlsx.docx.msi<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh98KqDbos6tXQKFW7XvpWQEZ01MliZU9jrLWAsCMijBeAeiKlmzKb_J5K1SU_VWv0NKF3Nlidx3i_zC7v7TyepGzjqzkg_kAQjEJ6f55oWtxMRi-hqKoUNxo7AxG75vusjoelNeTJ_Fg_Wn3Wl5TT3HXlX1RPOjhYrZeRz2qeiEUELmi58tPgd1GfSyCA\/s16000\/Atera%2520%28Source%2520-%2520Sublime%2520Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Atera (Source \u2013 Sublime Security)<\/figcaption><\/figure>\n<\/div>\n<p>This double extension technique exploits user expectations while hiding the executable nature of the payload.<\/p>\n<p>Upon execution, the malicious <a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponize-msi-packages-png-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">MSI package<\/a> initiates a multi-stage installation process. The Atera Agent installs through an attended process that requires user interaction, creating visible installation dialogs that appear legitimate.<\/p>\n<p>Simultaneously, two silent installations occur in the background: Splashtop Streamer and Microsoft .NET Runtime 8.<\/p>\n<p>These components download directly from their respective legitimate sources, generating network traffic that appears entirely benign to security monitoring systems.<\/p>\n<p>The attack\u2019s sophistication lies in its use of legitimate infrastructure for payload delivery. By downloading RMM components from official vendor websites rather than suspicious domains, the malware evades signature-based detection systems and network monitoring tools that typically flag downloads from known malicious sources.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Equip your SOC with full access to the latest threat data from\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0that can Improve incident response -&gt;\u00a0<strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn_aug&amp;utm_medium=article&amp;utm_campaign=how-to-get-real-time-iocs&amp;utm_content=feeds-cta1&amp;utm_term=050825#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 14-day\u00a0Free\u00a0Trial<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponizing-rmm-tools\/\">Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponizing-rmm-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data Cybercriminals are increasingly exploiting Remote Monitoring and Management (RMM) software to gain unauthorized access to corporate systems, with a sophisticated new attack campaign demonstrating how legitimate IT tools can become powerful weapons in the wrong hands. This emerging threat leverages the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5920","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5920"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5920"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5920\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5920"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5920"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5920"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}