Infosecurity Magazine reports that threat actors have leveraged fraudulent PayPal alerts to deploy legitimate remote monitoring and management tools in a bid to pilfer credentials as part of a phishing attack campaign.Intrusions commenced with the delivery of fake PayPal email alerts meant to create a sense of urgency, followed by phone-based social engineering that lured targets into downloading RMM software, with attackers initially launching LogMeIn Rescue before switching to AnyDesk, according to an analysis from Cyberproof. Such redundancy in RMM utilization, which was observed in an earlier Broadcom report, facilitates more clandestine phishing operations."While the immediate motivation behind this campaign appears financial, the long-term risk is significant. Access gained through these RMM 'backdoors' can be sold to Advanced Persistent Threat (APT) actors, leading to full corporate compromise or ransomware deployment," said CyberProof, which recommended the implementation of network access restrictions to typical RMM ports, up-to-date software, offline backups, and third-party RMM tool risk assessments to mitigate potential compromise.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds

