Author: Virus Bulletin - Bewertung: 0x - Views:5
Goodbye loaders, hello RMM: the rise of legit software in ecrime campaigns
Presented at the VB2025 conference in Berlin, 24 - 26 September 2025.
↓ Slides: N/A
↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2025/papers/Goodbye-loaders-hello-RMM-the-rise-of-legit-software-in-ecrime-campaigns.pdf
→ Details: https://www.virusbulletin.com/conference/vb2025/abstracts/goodbye-loaders-hello-rmm-rise-legit-software-ecrime-campaigns/
✪ PRESENTED BY ✪
• Selena Larson(Proofpoint)
• Ole Villadsen (Proofpoint)
✪ ABSTRACT ✪
Cybercriminals are increasingly using legitimate remote access software as an initial access method to deliver malware. Historically, threat actors delivering malware, including ransomware, used remote access software and remote monitoring and management (RMM) tools as part of an overall attack chain, typically once a host was already compromised. Now, tools like ScreenConnect, Atera and Bluetrait are often observed as the first step in an attack chain, delivered directly via phishing emails.
In this presentation we will discuss:
- Why and how the cybercrime initial access landscape has drastically shifted
- What are the most frequently observed RMM payloads
- How new techniques can bypass existing detections and how defenders can respond
Overall, this behaviour shift is notable. Proofpoint has observed multiple ecrime threat actors adopting RMMs in addition to, or instead of, their typical remote access trojans (RATs). Since mid-2024 threat actors have been using RMMs exponentially more than previously. And they're using a much wider variety of legitimate software and services, with our researchers now regularly observing at least 10 different RMM tools in email campaigns, up from just two to three from 2022 through mid-2024.
The increased use of RMM tooling also aligns with a decrease in prominent loader and botnet malware most often used by initial access brokers facilitating ransomware attacks. This is in part due to global law enforcement actions like Operation Endgame, which disrupted major malware infrastructure and imposed cost on multiple cybercriminal operations. While the IAB actors tracked by our researchers have not necessarily pivoted to RMM delivery via email, it is interesting to note the drastic shift in the landscape throughout 2024, and the increase in new and different tooling following the disruption of major botnets and loaders.
This has provided some benefits. Using RMMs often allows adversaries to bypass security protections that block known malware. It also may reduce user suspicion when they are directed to install something they know is "real". While this poses some challenges for defenders and enterprises, there are multiple best practices when it comes to hunting, detecting, and blocking execution of RMMs.
We will cover the dynamic shifts in the cybercrime threat landscape, how attack delivery has changed, the new risks posed to enterprises, and what we can do to combat these new techniques.