Threat reportMalwareTL-2026-2956

Action1 RMM Tool Abused via Phishing PDF Invoices and Malicious VBS/MSI Chain

highACTIVE

Action1 RMM Tool Abused via Phishing PDF Invoices and (TL-2026-2956) is a high-severity malware campaign, first published 2026-10-06. It has no confirmed attribution, affects Microsoft Windows (endpoints receiving the phishing PDF), maps to 10 MITRE ATT&CK techniques (T1036, T1059.005, T1071.001), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2956

Threat ID
TL-2026-2956
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
14

Malware and tooling in Action1 RMM Tool Abused via Phishing PDF Invoices and

Malware and tooling: Action1

How Action1 RMM Tool Abused via Phishing PDF Invoices and works

Phishing emails deliver fake PDF invoices whose OpenAction/URI keywords redirect victims to a VBS script hosted on a Vercel app. The script shows a decoy PDF while downloading an MSI that silently installs the legitimate Action1 RMM agent (A1Agent service), giving the operators remote access through what is probably a free or test Action1 account.

On 2026-10-06 SANS ISC handler Xavier Mertens documented a phishing campaign that abuses the legitimate Action1 remote monitoring and management (RMM) platform for remote access. The lure is a PDF attachment posing as an invoice. The PDF contains the 'OpenAction' and 'URI' keywords, so opening it sends the victim to a URL on a Vercel-hosted app (up-theta-rose.vercel.app). Because the malicious link sits inside the attachment and not in the message body, it sidesteps email filtering that inspects body URLs.

The URL delivers adobe_new_update.vbs, a VBS script that is not obfuscated. It has two jobs: it displays a legitimate-looking PDF decoy so the victim sees the expected document, and it downloads a second stage, action1.msi, from the same Vercel host. The MSI contains four unsigned files tied to the Action1 agent (a1_7z_dll_file, a1_sas_dll_file, action1_remote_exe and main_service_exe) and installs the A1Agent Windows service, which launches C:\Windows\Action1\action1_agent.exe automatically. Configuration, including the Action1 customer ID and connection details, is stored under HKLM\Software\Action1\Agent. The agent connects to the Action1 cloud endpoint server.na-2.action1.com using customer ID 49b18106-681d-456a-b098-092e2818c09a. The report notes the agent binary carries an Action1 Corporation signature whose certificate expired in May 2026.

The author's assessment is that the operators abuse the vendor's own cloud infrastructure, probably through a free or test Action1 account, which is the same pattern seen earlier with ScreenConnect. Since the payload is a legitimate, vendor-signed RMM agent talking to the vendor's cloud, antivirus and network allow-listing rarely flag it. The source gives no CVE, CVSS score or actor attribution, so severity is analyst-assigned.

This fits a wider pattern. Action1 abuse was first publicly reported in April 2023, when The DFIR Report and BleepingComputer described its use in ransomware intrusions including Monti. Huntress reported in January 2026 on Action1 being used to push ScreenConnect clients via MSI packages. Cloudflare Cloudforce One (2026-01-20) and ANY.RUN (2026-09-01) describe Vercel-hosted phishing kits that deliver VBS scripts and MSI packages for other RMM tools such as GoTo Resolve, ScreenConnect and ITarian. Those reports do not mention Action1 and are not confirmed to be the same operator. BeaconBeagle returned no records for up-theta-rose.vercel.app.

MITRE ATT&CK techniques used in TL-2026-2956

Defense Evasion

T1036 Masquerading; T1218.007 Msiexec

Execution

T1059.005 Visual Basic; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools

Persistence

T1543.003 Windows Service

Initial Access

T1566.001 Spearphishing Attachment

Resource Development

T1583.006 Web Services; T1608.001 Upload Malware

Affected products and versions in Action1 RMM Tool Abused via Phishing PDF Invoices and

  • Microsoft — Windows (endpoints receiving the phishing PDF)
  • Action1 Corporation — Action1 RMM agent (legitimate software abused; not a vulnerability)

Remediation for Action1 RMM Tool Abused via Phishing PDF Invoices and

Immediate actions

  • Block up-theta-rose.vercel.app and monitor/alert on egress to server.na-2.action1.com from hosts that do not run an approved Action1 deployment
  • Hunt for the A1Agent service, C:\Windows\Action1\action1_agent.exe and HKLM\Software\Action1\Agent, and match the customer ID against your own Action1 tenant
  • Isolate and reimage hosts where an unapproved Action1 agent is found; search mail logs for PDF attachments that contain OpenAction and URI actions

Workarounds

  • Set .vbs to open in a text editor by default or disable Windows Script Host where not needed
  • Restrict Windows Installer (msiexec) from running user-initiated MSI installs for standard users

Longer-term hardening

  • Maintain an allow-list of approved RMM tools and treat any unrecognised RMM agent as suspicious
  • Block or restrict execution of .vbs files from user-writable paths and downloads (WSH hardening)
  • Inspect PDF attachments for auto-launch actions and embedded URIs at the mail gateway
  • Report the abusing Action1 customer ID to Action1 so the account can be suspended

Timeline of Action1 RMM Tool Abused via Phishing PDF Invoices and

  • Action1 RMM abuse first publicly reported (The DFIR Report, BleepingComputer, April 2023), including use in ransomware intrusions such as Monti; Action1 responds with threat-actor filtering.
  • Start of the November 2025 to January 2026 period in which Cloudflare Cloudforce One observed Vercel-hosted phishing delivering RMM tools (GoTo Resolve); not confirmed to be the same operator.
  • Huntress reports Action1 used to distribute ScreenConnect clients via MSI packages (January 2026) and other daisy-chained rogue RMM installs.
  • Cloudflare Cloudforce One publishes its report on the Vercel-hosted RMM abuse campaign with Telegram-gated payload delivery.
  • Action1 Corporation code-signing certificate on the abused agent binaries expires (May 2026, per SANS ISC).
  • ANY.RUN publishes its analysis of a 46-country, Vercel-hosted phishing kit family that delivers legitimate RMM MSI packages via VBS.
  • SANS ISC handler Xavier Mertens publishes the diary on the PDF invoice, adobe_new_update.vbs and action1.msi chain that installs the Action1 agent.

Sources cited for Action1 RMM Tool Abused via Phishing PDF Invoices and

Detection coverage for TL-2026-2956

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2956 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats