# Action1 RMM Tool Abused via Phishing PDF Invoices and Malicious VBS/MSI Chain

> Phishing emails deliver fake PDF invoices whose OpenAction/URI keywords redirect victims to a VBS script hosted on a Vercel app. The script shows a decoy PDF while downloading an MSI that silently installs the legitimate Action1 RMM agent (A1Agent service), giving the operators remote access through what is probably a free or test Action1 account.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2956
- **ID:** TL-2026-2956
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-06 SANS ISC handler Xavier Mertens documented a phishing campaign that abuses the legitimate Action1 remote monitoring and management (RMM) platform for remote access. The lure is a PDF attachment posing as an invoice. The PDF contains the 'OpenAction' and 'URI' keywords, so opening it sends the victim to a URL on a Vercel-hosted app (up-theta-rose.vercel.app). Because the malicious link sits inside the attachment and not in the message body, it sidesteps email filtering that inspects body URLs.

The URL delivers adobe_new_update.vbs, a VBS script that is not obfuscated. It has two jobs: it displays a legitimate-looking PDF decoy so the victim sees the expected document, and it downloads a second stage, action1.msi, from the same Vercel host. The MSI contains four unsigned files tied to the Action1 agent (a1_7z_dll_file, a1_sas_dll_file, action1_remote_exe and main_service_exe) and installs the A1Agent Windows service, which launches C:\Windows\Action1\action1_agent.exe automatically. Configuration, including the Action1 customer ID and connection details, is stored under HKLM\Software\Action1\Agent. The agent connects to the Action1 cloud endpoint server.na-2.action1.com using customer ID 49b18106-681d-456a-b098-092e2818c09a. The report notes the agent binary carries an Action1 Corporation signature whose certificate expired in May 2026.

The author's assessment is that the operators abuse the vendor's own cloud infrastructure, probably through a free or test Action1 account, which is the same pattern seen earlier with ScreenConnect. Since the payload is a legitimate, vendor-signed RMM agent talking to the vendor's cloud, antivirus and network allow-listing rarely flag it. The source gives no CVE, CVSS score or actor attribution, so severity is analyst-assigned.

This fits a wider pattern. Action1 abuse was first publicly reported in April 2023, when The DFIR Report and BleepingComputer described its use in ransomware intrusions including Monti. Huntress reported in January 2026 on Action1 being used to push ScreenConnect clients via MSI packages. Cloudflare Cloudforce One (2026-01-20) and ANY.RUN (2026-09-01) describe Vercel-hosted phishing kits that deliver VBS scripts and MSI packages for other RMM tools such as GoTo Resolve, ScreenConnect and ITarian. Those reports do not mention Action1 and are not confirmed to be the same operator. BeaconBeagle returned no records for up-theta-rose.vercel.app.

## MITRE ATT&CK

- T1583.006 Web Services
- T1608.001 Upload Malware
- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1059.005 Visual Basic
- T1036 Masquerading
- T1218.007 Msiexec
- T1543.003 Windows Service
- T1219 Remote Access Tools
- T1071.001 Web Protocols

## Sources

- [More RMM Tools In the Wild (Xavier Mertens, SANS ISC)](https://isc.sans.edu/diary/rss/33400)
- [Vercel-hosted RMM abuse campaign evolves with Telegram C2 for victim filtering (Cloudflare Cloudforce One)](https://www.cloudflare.com/cloudforce-one/research/report/vercel-hosted-rmm-abuse-campaign-evolves-with-telegram-c2-for-victim-filtering/)
- [A single Canadian tax lure spread into a 46-country, US-first RMM campaign (ANY.RUN via HackerNoon)](https://hackernoon.com/a-single-canadian-tax-lure-spread-into-a-46-country-us-first-rmm-campaign)
- [Daisy-Chaining Rogue RMM Tools: How Threat Actors Abuse Remote Management Software for Initial Access (Huntress)](https://www.huntress.com/blog/daisy-chaining-rogue-rmm-tools)
- [Hackers start abusing Action1 RMM in ransomware attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/security/hackers-start-abusing-action1-rmm-in-ransomware-attacks/)
- [Action1 launches threat actor filtering to block remote management platform abuse (CSO Online)](https://www.csoonline.com/article/3681933/action1-launches-threat-actor-filtering-to-block-remote-management-platform-abuse.html)
- [Weaponized RMM: Hunting the Adversary Abuse of Remote Monitoring Tools (Netlas)](https://netlas.io/blog/index/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2956
