RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress
Remote management tools are increasingly weaponized by attackers, with RMM abuse now appearing in nearly 40% of Huntress investigations following a 277% spike in incidents. The article examines how adversaries exploit these trusted access mechanisms and provides defensive strategies to prevent misuse of remote access tools.
A malware campaign discovered by Cato Networks exploits sponsored search ads to direct macOS users to a fake OpenAI Codex download page, where victims are socially engineered into pasting malicious commands directly into Terminal. The attack uses a variation of the ClickFix technique, which manipulates users into executing the infection themselves rather than opening a malicious file, with the campaign beginning through sponsored search results for queries like "codex macos download."
Researchers have identified a novel command-and-control technique where threat actors exploit FTP banners as dead drop resolvers to deliver two previously unreported RATs named E4del and PINHOLE. This approach leverages legitimate FTP services to obscure malware communications and point to additional C2 infrastructure while evading detection.
Kaspersky researchers have identified the first malware specifically designed to target car head units, which has been enlisted into the BadBox botnet infrastructure. The discovery represents a significant expansion of botnet operations into automotive systems, with the malware already compromising millions of devices across the network.
Threat actors continue distributing WeedHack malware to Minecraft players through counterfeit game clients, maintaining operations even after law enforcement dismantled the malware's original infrastructure in July. The persistence of this campaign demonstrates how attackers adapt their distribution channels when primary infrastructure is disrupted, keeping a known threat active against gaming communities.