# Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaign

> Active phishing campaigns weaponize fake Zoom, Microsoft Teams, and Google Meet meeting invites to deliver digitally signed Remote Monitoring and Management (RMM) tools — Datto RMM, LogMeIn Unattended, and ScreenConnect — as malicious payloads. Victims are lured to pixel-perfect typo-squatted domains (e.g., zoom-meet.us) where a 'mandatory software update' social engineering hook tricks corporate users into downloading and executing signed RMM agents. Because these tools are legitimate, digitally signed software commonly pre-approved in enterprise environments, they bypass signature-based security controls, EDR, and application allowlists. Once installed, attackers gain full administrative remote access — file transfer, remote shell, screen sharing, lateral movement, and the ability to mass-deploy ransomware via the RMM's own infrastructure. Discovered and tracked by Netskope Threat Labs. CISA previously warned about identical RMM weaponization patterns in advisory AA23-025A (January 2023), confirming this is an ESCALATING trend, not a one-off campaign.

- **Published:** 2026-02-12T21:58:00Z
- **Last reviewed:** 2026-02-12T21:58:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0079
- **ID:** TL-2026-0079
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 12 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Netskope Threat Labs is tracking multiple concurrent phishing campaigns that exploit the high-trust, high-frequency nature of corporate video conferencing. The attack chain operates in three stages:

**Stage 1 — The Bait:** Attackers send phishing emails containing fake meeting invitations for Zoom, Microsoft Teams, or Google Meet. The invites appear legitimate and often reference scheduled business meetings, creating urgency. Links redirect to typo-squatted domains (e.g., zoom-meet.us) hosting pixel-perfect replicas of the legitimate video conferencing landing pages. To enhance credibility, the phishing pages display lists of participants who have 'joined' the call, with additional participants appearing dynamically to create the illusion of a live meeting.

**Stage 2 — The Hook:** When the victim attempts to join the fake meeting, a notification indicates their application is 'out of date' or 'incompatible.' The victim must download and execute a provided 'software update' before they can join. This leverages two psychological pressures: (1) urgency to join a business meeting they believe is happening NOW, and (2) the update appears to be a legitimate technical requirement. Some phishing sites provide step-by-step installation instructions, further legitimizing the payload. The social engineering is specifically designed to make victims manually bypass security warnings.

**Stage 3 — The Payload:** The 'update' is a digitally signed executable or MSI installer containing a legitimate RMM tool. Binaries are renamed to match the expected platform: GoogleMeeet.exe, ZoomWorkspaceinstallersetup.msi, etc. Three primary RMM agents identified: (1) Datto RMM — legitimate IT management platform, (2) LogMeIn Unattended — remote access tool designed for unattended access, (3) ScreenConnect (ConnectWise Control) — remote support and access software. All three are digitally signed by their legitimate publishers, meaning they pass code signing verification and may be pre-approved in enterprise application allowlists.

**Post-Exploitation:** Once the RMM agent is installed, attackers have full administrative access via the tool's native capabilities: file transfer for data exfiltration, remote shell for command execution, screen sharing for reconnaissance, and mass software deployment for pushing additional malware across the network. The RMM's own infrastructure serves as the C2 channel — completely blending with legitimate corporate traffic. A single compromised endpoint can escalate to full-scale corporate breach through lateral movement using the RMM's built-in deployment features.

**Historical Context:** CISA, NSA, and MS-ISAC issued joint advisory AA23-025A (January 2023) warning about identical patterns — phishing leading to ScreenConnect and AnyDesk deployment for financial fraud. That campaign targeted FCEB (Federal Civilian Executive Branch) networks using help desk-themed lures. The current Netskope-tracked campaigns represent an EVOLUTION: updated lures (video conferencing instead of help desk), broader RMM tool selection (adding Datto RMM and LogMeIn), and improved phishing page quality (dynamic participant lists). The Living-off-the-Land (LOtL) approach using signed RMM tools is becoming the PREFERRED initial access method for both financially motivated actors and APTs because it eliminates the need for custom malware development entirely.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1218 System Binary Proxy Execution
- T1553 Subvert Trust Controls
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1072 Software Deployment Tools
- T1005 Data from Local System
- T1113 Screen Capture
- T1041 Exfiltration Over C2 Channel
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1486 Data Encrypted for Impact
- T1082 System Information Discovery
- T1018 Remote System Discovery
- T1056 Input Capture
- T1087 Account Discovery
- T1608 Stage Capabilities
- T1685 Disable or Modify Tools

## Sources

- [Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures — Netskope Threat Labs](https://www.netskope.com/blog/attackers-weaponize-signed-rmm-tools-via-zoom-meet-teams-lures)
- [CISA/NSA/MS-ISAC Joint Advisory AA23-025A — Protecting Against Malicious Use of Remote Monitoring and Management Software](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a)
- [MITRE ATT&CK T1219 — Remote Access Tools](https://attack.mitre.org/techniques/T1219/)
- [ConnectWise ScreenConnect Critical Vulnerabilities CVE-2024-1709/CVE-2024-1708 — Post-Exploitation in the Wild](https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708)
- [Symantec ISTR — Living off the Land and Fileless Attack Techniques](https://www.symantec.com/content/dam/symantec/docs/security-center/white-papers/istr-living-off-the-land-and-fileless-attack-techniques-en.pdf)
- [CrowdStrike Global Threat Report — Remote Access Tool Abuse by Nation-State and Criminal Actors](https://go.crowdstrike.com/rs/281-OBQ-266/images/15GlobalThreatReport.pdf)
- [Silent Push — Large Phishing Operation with Typosquatted Domains (Amazon, Microsoft, Geek Squad)](https://www.silentpush.com/blog/silent-push-uncovers-a-large-phishing-operation-featuring-amazon-geek-squad-mcafee-microsoft-norton-and-paypal-domains)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0079
