Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityMicrosoft got hacked, and somehow Clippy ended up in a crypto scheme(02.10.2026 um 14:11 Uhr)
•
Windows Tipps & SecurityBank-Überweisung: Dieser Fehler kann zur Sperrung Ihres Kontos führen(02.10.2026 um 14:30 Uhr)
••
Sichere ProgrammierungLog Safety Events, Not Full Transcripts: One Audit Trade-Off(02.10.2026 um 14:10 Uhr)
•••••
Sichere ProgrammierungBuild a Python Subtitle Generator with ffmpeg: A Step-by-Step Guide(02.10.2026 um 14:14 Uhr)
•
Sichere Programmierung🔐 Vault — Privacy-First Local AI for Sensitive Legal Documents(02.10.2026 um 14:14 Uhr)
•
Windows Tipps & SecurityMicrosoft got hacked, and somehow Clippy ended up in a crypto scheme(02.10.2026 um 14:11 Uhr)
•
Windows Tipps & SecurityBank-Überweisung: Dieser Fehler kann zur Sperrung Ihres Kontos führen(02.10.2026 um 14:30 Uhr)
••
Sichere ProgrammierungLog Safety Events, Not Full Transcripts: One Audit Trade-Off(02.10.2026 um 14:10 Uhr)
•••••
Sichere ProgrammierungBuild a Python Subtitle Generator with ffmpeg: A Step-by-Step Guide(02.10.2026 um 14:14 Uhr)
•
Sichere Programmierung🔐 Vault — Privacy-First Local AI for Sensitive Legal Documents(02.10.2026 um 14:14 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Youtube virusbtn: Goodbye loaders, hello RMM: the rise of legit software in ecrime campaigns

Video von Youtube virusbtn auf YouTube: Author: Virus Bulletin - Bewertung: 0x - Views:5 Goodbye loaders, hello RMM: the rise of legit software in ecrime…

HD Video
Goodbye loaders, hello RMM: the rise of legit software in ecrime campaigns
Video abspielen
Beitrag
0
Seite
0
↗ Quelle (youtube.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Author: Virus Bulletin - Bewertung: 0x - Views:5

Goodbye loaders, hello RMM: the rise of legit software in ecrime campaigns



Presented at the VB2025 conference in Berlin, 24 - 26 September 2025.

↓ Slides: N/A

↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/papers/Goodbye-loaders-hello-RMM-the-rise-of-legit-software-in-ecrime-campaigns.pdf

→ Details: https://www.virusbulletin.com/conference/vb2025/abstracts/goodbye-loaders-hello-rmm-rise-legit-software-ecrime-campaigns/



✪ PRESENTED BY ✪



• Selena Larson(Proofpoint)

• Ole Villadsen (Proofpoint)



✪ ABSTRACT ✪



Cybercriminals are increasingly using legitimate remote access software as an initial access method to deliver malware. Historically, threat actors delivering malware, including ransomware, used remote access software and remote monitoring and management (RMM) tools as part of an overall attack chain, typically once a host was already compromised. Now, tools like ScreenConnect, Atera and Bluetrait are often observed as the first step in an attack chain, delivered directly via phishing emails.



In this presentation we will discuss:



- Why and how the cybercrime initial access landscape has drastically shifted

- What are the most frequently observed RMM payloads

- How new techniques can bypass existing detections and how defenders can respond



Overall, this behaviour shift is notable. Proofpoint has observed multiple ecrime threat actors adopting RMMs in addition to, or instead of, their typical remote access trojans (RATs). Since mid-2024 threat actors have been using RMMs exponentially more than previously. And they're using a much wider variety of legitimate software and services, with our researchers now regularly observing at least 10 different RMM tools in email campaigns, up from just two to three from 2022 through mid-2024.



The increased use of RMM tooling also aligns with a decrease in prominent loader and botnet malware most often used by initial access brokers facilitating ransomware attacks. This is in part due to global law enforcement actions like Operation Endgame, which disrupted major malware infrastructure and imposed cost on multiple cybercriminal operations. While the IAB actors tracked by our researchers have not necessarily pivoted to RMM delivery via email, it is interesting to note the drastic shift in the landscape throughout 2024, and the increase in new and different tooling following the disruption of major botnets and loaders.



This has provided some benefits. Using RMMs often allows adversaries to bypass security protections that block known malware. It also may reduce user suspicion when they are directed to install something they know is "real". While this poses some challenges for defenders and enterprises, there are multiple best practices when it comes to hunting, detecting, and blocking execution of RMMs.



We will cover the dynamic shifts in the cybercrime threat landscape, how attack delivery has changed, the new risks posed to enterprises, and what we can do to combat these new techniques.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
3 belegte Techniken
T1486TA0040 · Impact
Data Encrypted for Impact
Mitigation: M1053 Data Backup & Offline Isolation
Quelle: Kontext-Klassifikation des Artikeltextes
T1071TA0011 · Command and Control
Application Layer Protocol (C2)
Mitigation: M1031 Network Intrusion Prevention & Egress Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
T1566TA0001 · Initial Access
Phishing
Mitigation: M1054 User Training & Email Gateway Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Goodbye loaders, hello RMM: the rise of legit software in ecrime campaigns

Thematisch verwandte Begriffe: Goodbye, loaders, hello, rise · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag