Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaign — Threadlinqs Intelligence
As of 2026-05-30, Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaign is a critical-severity malware threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0079 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: N/A · FINANCIAL
Active phishing campaigns weaponize fake Zoom, Microsoft Teams, and Google Meet meeting invites to deliver digitally signed Remote Monitoring and Management (RMM) tools — Datto RMM, LogMeIn
Netskope Threat Labs is tracking multiple concurrent phishing campaigns that exploit the high-trust, high-frequency nature of corporate video conferencing. The attack chain operates in three stages:
**Stage 1 — The Bait:** Attackers send phishing emails containing fake meeting invitations for Zoom, Microsoft Teams, or Google Meet. The invites appear legitimate and often reference scheduled business meetings, creating urgency. Links redirect to typo-squatted domains (e.g., zoom-meet.us) hosting pixel-perfect replicas of the legitimate video conferencing landing pages. To enhance credibility, the phishing pages display lists of participants who have 'joined' the call, with additional participants appearing dynamically to create the illusion of a live meeting.
**Stage 2 — The Hook:** When the victim attempts to join the fake meeting, a notification indicates their application is 'out of date' or 'incompatible.' The victim must download and execute a provided 'software update' before they can join. This leverages two psychological pressures: (1) urgency to join a business meeting they believe is happening NOW, and (2) the update appears to be a legitimate technical requirement. Some phishing sites provide step-by-step installation instructions, further legitimizing the payload. The social engineering is specifically designed to make victims manually bypass security warnings.
**Stage 3 — The Payload:** The 'update' is a digitally signed executable or MSI installer containing a legitimate RMM tool. Binaries are renamed to match the expected platform: GoogleMeeet.exe, ZoomWorkspaceinstallersetup.msi, etc. Three primary RMM agents identified: (1) Datto RMM — legitimate IT management platform, (2) LogMeIn Unattended — remote access tool designed for unattended access, (3) ScreenConnect (ConnectWise Control) — remote support and access software. All three are digitally signed by their legitimate publishers, meaning they pass code signing verification and may be pre-approved in enterprise application allowlists.
**Post-Exploitation:** Once the RMM agent is installed, attackers have full administrative access via the tool's native capabilities: file transfer for data exfiltration, remote shell for command execution, screen sharing for reconnaissance, and mass software deployment for pushing additional malware across the network. The RMM's own infrastructure serves as the C2 channel — completely blending with legitimate corporate traffic. A single compromised endpoint can escalate to full-scale corporate breach through lateral movement using the RMM's built-in deployment features.
**Historical Context:** CISA, NSA, and MS-ISAC issued joint advisory AA23-025A (January 2023) warning about identical patterns — phishing leading to ScreenConnect and AnyDesk deployment for financial fraud. That campaign targeted FCEB (Federal Civilian Executive Branch) networks using help desk-themed lures. The current Netskope-tracked campaigns represent an EVOLUTION: updated lures (video conferencing instead of help desk), broader RMM tool selection (adding Datto RMM and LogMeIn), and improved phishing page quality (dynamic participant lists). The Living-off-the-Land (LOtL) approach using signed RMM tools is becoming the PREFERRED initial access method for both financially motivated actors and APTs because it eliminates the need for custom malware development entirely.
Weaknesses (CWE)
CWE-451, CWE-494, CWE-829, CWE-345
Target sectors: Technology, Financial Services, Healthcare, Government, Professional Services, Manufacturing, Education
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1566, T1566, T1204, T1204, T1543, T1547, T1036, T1036, T1218, T1553