Find notable cyber news and cases, enriched with sources, timelines, and signals.

Booby-trapped installers deploying ScreenConnect and other RMM tools

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

Attackers are using booby-trapped MSI installers and executables to deploy legitimate RMM tools and gain covert remote access inside targeted networks. The malware activity matters because the tools can be used for credential harvesting, system reconnaissance, and deeper post-compromise access while looking like normal enterprise software. The current wave uses ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve as the delivery outcome.

Related Happenings

SSHStalker IRC-controlled Linux botnet

Malware Activity
H score23 First: 11.02.2026 11:56 Last: 11.02.2026 11:56 Sources 1

About this happening: Researchers disclosed SSHStalker, a Linux botnet that uses IRC C2 and automated SSH scanning to compromise exposed systems, increasing the risk of persistent contr...

Greenvelope phishing-to-LogMeIn Resolve dual-vector campaign

Campaign
H score31 First: 23.01.2026 13:18 Last: 23.01.2026 13:18 Sources 1

About this happening: A dual-vector phishing campaign is using fake Greenvelope invitations and stolen credentials to establish persistent remote access on compromised hosts, turning le...

ScreenConnect and NetSupport abuse for freight cargo hijacking

Malware Activity
H score29 First: 03.11.2025 18:46 Last: 03.11.2025 18:46 Sources 1

About this happening: Malicious deployment of ScreenConnect, NetSupport, and related RMM tools is giving attackers remote control over freight-broker and trucking carrier systems, e...

Syncro MSP agent deploying ScreenConnect for remote access

Malware Activity
H score20 First: 15.10.2025 22:22 Last: 15.10.2025 22:22 Sources 1

About this happening: The Syncro payload installs ScreenConnect through a hidden remote-management agent, giving operators remote access to infected endpoints and a path to follow-on payl...

APT phishing campaign abusing ScreenConnect, AnyDesk, and Atera

Campaign
H score33 First: 13.10.2025 18:45 Last: 13.10.2025 18:45 Sources 1

About this happening: A wave of phishing-led RMM abuse is giving APT groups initial access to systems and enabling persistence plus lateral movement inside compromised networks. The act...

Timeline

  1. 03.11.2025 15:18 2 articles · 8mo ago

    Booby-trapped installers deploy ScreenConnect and other RMM tools in logistics intrusions

    Initial Disclosure

    Attackers targeting trucking and logistics companies use compromised-email, spear-phishing, and fraudulent freight-listing lures to deliver booby-trapped MSI installers or executables that install legitimate RMM tools such as ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve. In some intrusions, PDQ Connect is used to drop and install ScreenConnect and SimpleHelp, and the resulting access is then used for system and network reconnaissance and credential harvesting with WebBrowserPassView.

    Show sources