Threat reportMalwareTL-2026-0079

Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaign

criticalACTIVE

Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures (TL-2026-0079) is a critical-severity malware campaign, first published 2026-02-12. It has no confirmed attribution, maps to 25 MITRE ATT&CK techniques (T1005, T1018, T1021), and is covered by 12 detection rules and 32 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
12SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0079

Threat ID
TL-2026-0079
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
Technology, Financial Services, Healthcare, Government, Professional Services, Manufacturing, Education
Target regions
North America, Europe, Global
Detection rules
12
Indicators of compromise
32

Malware and tooling in Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures

Malware and tooling: Datto RMM agent — legitimate IT management tool weaponized as phishing payload for persistent remote administrative access, LogMeIn Unattended — legitimate remote access tool weaponized as phishing payload, designed for unattended access (no user interaction needed after install), ScreenConnect (ConnectWise Control) — legitimate remote support tool weaponized as phishing payload. Previously exploited via CVE-2024-1709/CVE-2024-1708

How Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures works

Active phishing campaigns weaponize fake Zoom, Microsoft Teams, and Google Meet meeting invites to deliver digitally signed Remote Monitoring and Management (RMM) tools — Datto RMM, LogMeIn Unattended, and ScreenConnect — as malicious payloads. Victims are lured to pixel-perfect typo-squatted domains (e.g., zoom-meet.us) where a 'mandatory software update' social engineering hook tricks corporate users into downloading and executing signed RMM agents. Because these tools are legitimate, digitally signed software commonly pre-approved in enterprise environments, they bypass signature-based security controls, EDR, and application allowlists. Once installed, attackers gain full administrative remote access — file transfer, remote shell, screen sharing, lateral movement, and the ability to mass-deploy ransomware via the RMM's own infrastructure. Discovered and tracked by Netskope Threat Labs. CISA previously warned about identical RMM weaponization patterns in advisory AA23-025A (January 2023), confirming this is an ESCALATING trend, not a one-off campaign.

Netskope Threat Labs is tracking multiple concurrent phishing campaigns that exploit the high-trust, high-frequency nature of corporate video conferencing. The attack chain operates in three stages:

**Stage 1 — The Bait:** Attackers send phishing emails containing fake meeting invitations for Zoom, Microsoft Teams, or Google Meet. The invites appear legitimate and often reference scheduled business meetings, creating urgency. Links redirect to typo-squatted domains (e.g., zoom-meet.us) hosting pixel-perfect replicas of the legitimate video conferencing landing pages. To enhance credibility, the phishing pages display lists of participants who have 'joined' the call, with additional participants appearing dynamically to create the illusion of a live meeting.

**Stage 2 — The Hook:** When the victim attempts to join the fake meeting, a notification indicates their application is 'out of date' or 'incompatible.' The victim must download and execute a provided 'software update' before they can join. This leverages two psychological pressures: (1) urgency to join a business meeting they believe is happening NOW, and (2) the update appears to be a legitimate technical requirement. Some phishing sites provide step-by-step installation instructions, further legitimizing the payload. The social engineering is specifically designed to make victims manually bypass security warnings.

**Stage 3 — The Payload:** The 'update' is a digitally signed executable or MSI installer containing a legitimate RMM tool. Binaries are renamed to match the expected platform: GoogleMeeet.exe, ZoomWorkspaceinstallersetup.msi, etc. Three primary RMM agents identified: (1) Datto RMM — legitimate IT management platform, (2) LogMeIn Unattended — remote access tool designed for unattended access, (3) ScreenConnect (ConnectWise Control) — remote support and access software. All three are digitally signed by their legitimate publishers, meaning they pass code signing verification and may be pre-approved in enterprise application allowlists.

**Post-Exploitation:** Once the RMM agent is installed, attackers have full administrative access via the tool's native capabilities: file transfer for data exfiltration, remote shell for command execution, screen sharing for reconnaissance, and mass software deployment for pushing additional malware across the network. The RMM's own infrastructure serves as the C2 channel — completely blending with legitimate corporate traffic. A single compromised endpoint can escalate to full-scale corporate breach through lateral movement using the RMM's built-in deployment features.

**Historical Context:** CISA, NSA, and MS-ISAC issued joint advisory AA23-025A (January 2023) warning about identical patterns — phishing leading to ScreenConnect and AnyDesk deployment for financial fraud. That campaign targeted FCEB (Federal Civilian Executive Branch) networks using help desk-themed lures. The current Netskope-tracked campaigns represent an EVOLUTION: updated lures (video conferencing instead of help desk), broader RMM tool selection (adding Datto RMM and LogMeIn), and improved phishing page quality (dynamic participant lists). The Living-off-the-Land (LOtL) approach using signed RMM tools is becoming the PREFERRED initial access method for both financially motivated actors and APTs because it eliminates the need for custom malware development entirely.

MITRE ATT&CK techniques used in TL-2026-0079

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture

discovery

T1018 Remote System Discovery; T1082 System Information Discovery; T1087 Account Discovery

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

defense-evasion

T1036 Masquerading; T1218 System Binary Proxy Execution

exfiltration

T1041 Exfiltration Over C2 Channel

command-and-control

T1071 Application Layer Protocol; T1219 Remote Access Tools; T1573 Encrypted Channel

execution

T1072 Software Deployment Tools; T1204 User Execution

impact

T1486 Data Encrypted for Impact

persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

initial-access

T1566 Phishing

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

Remediation for Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures

Immediate actions

  • Block known typo-squatted video conferencing domains at DNS/proxy level (zoom-meet.us and similar)
  • Deploy application control policies to prevent unauthorized RMM tool installation — whitelist only IT-approved RMM agents by publisher + hash
  • Alert security teams to the 'mandatory software update' social engineering pattern — users should NEVER install software from meeting invite links
  • Review network logs for unexpected RMM tool installations in the past 90 days — Datto RMM, LogMeIn Unattended, ScreenConnect on non-IT endpoints

Workarounds

  • Use browser-based video conferencing only (no downloaded clients) to eliminate the 'software update' social engineering vector
  • Configure email gateways to quarantine messages containing video conferencing URLs that don't match corporate-approved domains
  • Implement network-level RMM tool blocking for all tools not in the corporate-approved list

Longer-term hardening

  • Implement Zero Trust application installation policies — users cannot install ANY software without IT approval regardless of digital signature
  • Deploy DNS sinkholing for all registered typosquats of Zoom, Teams, and Meet domains
  • Configure EDR to alert on any RMM tool execution NOT initiated by IT support teams
  • Establish video conferencing hygiene training — verify meeting URLs directly from calendar invites, never from email links
  • Monitor for new RMM tool processes on endpoints that aren't in the IT-managed fleet

Weaknesses (CWE) in Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures

CWE-451, CWE-494, CWE-829, CWE-345

Timeline of Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures

  • CISA identifies first widespread RMM phishing campaign targeting FCEB networks using help desk-themed lures delivering ScreenConnect and AnyDesk. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
  • CISA confirms bi-directional traffic between FCEB network and myhelpcare[.]cc — active RMM-based compromise of federal civilian networks. Source: CISA AA23-025A
  • Silent Push uncovers large-scale phishing operation with typosquatted domains impersonating Amazon, Microsoft, Geek Squad, McAfee, Norton, and PayPal — RMM tools as payloads. Source: https://www.silentpush.com/blog/
  • CISA, NSA, and MS-ISAC publish joint advisory AA23-025A warning about malicious use of legitimate RMM software — portable executables bypass admin privilege requirements and common software controls. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
  • ConnectWise ScreenConnect critical vulnerabilities CVE-2024-1709 (authentication bypass) and CVE-2024-1708 (path traversal) disclosed — mass exploitation in the wild. Attackers who already deployed ScreenConnect via phishing could exploit these to expand access. Source: Huntress
  • CrowdStrike and Symantec Global Threat Reports confirm Remote Access Tool abuse as the dominant Living-off-the-Land technique for both APT and financially motivated actors throughout 2024-2025. Source: CrowdStrike/Symantec
  • Payloads disguised with video conferencing platform names: GoogleMeeet.exe, ZoomWorkspaceinstallersetup.msi — maintaining deception through the download and execution chain. Source: Netskope Threat Labs
  • Three primary RMM agents confirmed as payloads: Datto RMM, LogMeIn Unattended, and ScreenConnect (ConnectWise Control) — all digitally signed, all capable of full remote administration. Source: Netskope Threat Labs
  • Netskope identifies typo-squatted domains including zoom-meet.us hosting pixel-perfect video conferencing phishing pages with dynamic participant joining simulation. Source: Netskope Threat Labs
  • Netskope Threat Labs publishes research on evolved RMM phishing campaigns — video conference lures (Zoom, Teams, Meet) with pixel-perfect phishing pages, dynamic participant lists, and 'mandatory software update' hook delivering Datto RMM, LogMeIn Unattended, and ScreenConnect. Source: https://www.netskope.com/blog/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures
  • As of 2026-05-29, this signed-RMM phishing campaign remains ACTIVE and escalating: Microsoft Defender Experts (Mar 2026) and ANY.RUN (Apr-May 2026, ~160 links/~80 domains hitting US orgs) confirm ongoing waves. No CVE to patch, no takedown or attribution; the unknown actor still operates, so ACTIVE stands.

Sources cited for Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures

Detection coverage for TL-2026-0079

As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0079 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats