# RMM tools distributed via phishing: ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud and N-able abused for remote access

> AhnLab ASEC reports ongoing phishing campaigns, first seen in January 2026, that deliver legitimate Remote Monitoring and Management (RMM) agents (ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud, N-able) to victims. Because the binaries are legitimately signed tools without malware signatures, they evade traditional detection while giving operators interactive remote access.

- **Published:** 2026-10-01T00:00:00Z
- **Last reviewed:** 2026-10-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3037
- **ID:** TL-2026-3037
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

AhnLab Security Intelligence Center (ASEC) published on 2026-10-01 an analysis of phishing campaigns that distribute six legitimate RMM products instead of custom malware. The activity was first detected in January 2026 and is ongoing. The tools are real vendor software configured with attacker-controlled tenant, server or account identifiers, so the endpoint shows a signed, trusted agent beaconing to an attacker-controlled instance.

Delivery varies by tool. ScreenConnect is delivered through LNK, BAT and VBS email attachments with deceptive names (Dropbox.SharedfilePDF.LNK, ZoomSetup-V.7.3.Bat, Wire Receipt Form_pdf.Vbs); the C2 server and port are embedded in the installer execution arguments, and ScreenConnect.ClientSetup.msi was fetched from attacker hosts such as 216.250.252.58:8040 and admin.lukiku.lol (relay.lukiku.lol observed as relay). FleetDeck is delivered through PDF documents with clickable links that download an installer; a deployment ID appended to the end of the file is passed as the -deploymentID argument (fleetdeck_agent_svc.exe -deploymentID <uuid> -askForName=0). ASEC associates FleetDeck use with Scattered Spider, which previously distributed DragonForce ransomware. Datto RMM is delivered through PDFs showing a fake Adobe Acrobat Pro update prompt that downloads AdrAcroPro11.2_3D_client.Exe; the CagService.Exe.Config file holds an AccountUid that identifies the operator. SimpleHelp is delivered through HTML phishing scripts, with the C2 server address stored hex-encoded in the sg_servers configuration entry; ASEC notes SimpleHelp abuse in Play, Medusa and ALPHV (BlackCat) intrusions. JumpCloud is delivered through phishing pages impersonating Adobe security documents; batch malware downloads and runs the agent with the operator's CONNECT_KEY argument. N-able is delivered through batch malware disguised as DocuSign Viewer that shows a fake DocuSign page while installing the agent; its settings.Ini contains the operator email mark@hessattorneys.co.za.

Corroborating public reporting shows the same technique class at scale: ANY.RUN research (published 2026-08-25) tracked 425 phishing-kit URLs across 240 hosts between 5 February and 29 July 2026 in 46 countries (about 45% US), with 94% of hosts live for a single day, and lures impersonating tax agencies, Social Security, Adobe, invoices, shipping and DocuSign. Red Canary and Zscaler (2025-09-12) documented ITarian, PDQ, SimpleHelp and Atera delivered via fake browser updates, fake Teams/Zoom/Excel updates, e-invite lures and government-form lures, with dual-RMM redundancy (SimpleHelp followed by ScreenConnect) and follow-on payloads such as HijackLoader and DeerStealer. Netlas (2026-06-05) lists MuddyWater, Hive affiliates, Storm-1811 and RansomHub as RMM abusers. No CVE is involved; the risk is abuse of legitimate functionality, so detection must rely on allow-listing approved RMM products and tenant IDs, and on behavioral telemetry (unexpected RMM installs, LNK/BAT/VBS launching installers, msiexec fetching from non-vendor hosts).

## MITRE ATT&CK

- T1583.001 Domains
- T1608.001 Upload Malware
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1204.001 Malicious Link
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1219.002 Remote Desktop Software

## Sources

- [RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able) - AhnLab ASEC](https://asec.ahnlab.com/en/95751/)
- [RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools - eSecurityPlanet (ANY.RUN research)](https://www.esecurityplanet.com/phishing/news-rmm-phishing-remote-access/)
- [Phishing RMM tools - Zscaler ThreatLabz](https://www.zscaler.com/blogs/cybersecurity-best-practices/phishing-rmm-tools)
- [Phishing RMM tools - Red Canary Intelligence](https://redcanary.com/blog/threat-intelligence/phishing-rmm-tools/)
- [Weaponized RMM: Hunting the Adversary Abuse of Remote Monitoring Tools - Netlas](https://netlas.io/blog/weaponized_rmm/)
- [Phishing Campaigns Drop RMM Tools for Remote Access - Infosecurity Magazine](https://infosecurity-magazine.com/news/phishing-campaigns-rmm-tools)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3037
