<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rmm-Abuse on CuraSec</title><link>https://curasec.metacog.co.kr/tags/rmm-abuse/</link><description>Recent content in Rmm-Abuse on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/rmm-abuse/index.xml" rel="self" type="application/rss+xml"/><item><title>Fake Adobe/Zoom Update Lures Deploy ScreenConnect RMM (SMOKE#SCREEN)</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-fake-adobe-and-zoom-updates-install-screenconnect-for-persis/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-fake-adobe-and-zoom-updates-install-screenconnect-for-persis/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit endpoints for unauthorized ScreenConnect installations and enforce application control policies that block unsanctioned RMM tools; no software vulnerability to patch, but tightening allow-lists prevents this class of persistence.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active campaign — hunt for ScreenConnect processes spawned by fake update installers or document-review lures; tune EDR/SIEM rules to flag unsanctioned RMM tool execution, mapping to ATT&amp;amp;CK T1219 and T1566.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A recurring pattern of RMM-as-backdoor via lure campaigns; reinforces the need for ongoing phishing simulation and user awareness around unsolicited software update prompts, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>Operation BlueDash Uses Fake Teams Update to Drop RMM Tools</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-operation-bluedash-deploys-level-rmm-and-screenconnect-via-f/</link><pubDate>Mon, 27 Jul 2026 13:44:31 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-operation-bluedash-deploys-level-rmm-and-screenconnect-via-f/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No patch or config action — this is a social-engineering delivery chain, not a software vulnerability. Worth knowing that legitimate RMM binaries (Level RMM, ScreenConnect) are being weaponized so anomalous installations can be flagged during code-review or build-pipeline audits.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active campaign uses a fake Microsoft Teams update lure to drop legitimate RMM tools that provide persistent remote access; hunt for unexpected Level RMM or ScreenConnect processes spawned from browser or user-space paths, and tune detections for counterfeit Microsoft Store redirect chains since Teams-themed lures are a high-volume enterprise vector.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Noteworthy campaign pattern — abusing legitimate RMM software bypasses many controls — but no named vendor breach or regulatory trigger; file for context when briefing on social-engineering trends or evaluating security-awareness training priorities.&lt;/li>
&lt;/ul></description></item></channel></rss>