HomeSecurityHackers gain initial access to organizations with RMM tools

Hackers gain initial access to organizations with RMM tools

Hackers are conducting an advanced cyber-attack campaign that leverages legitimate Remote Monitoring and Management tools (Remote Monitoring and Management – RMM) and has emerged as a significant threat to European organizations, especially in France and Luxembourg.

See also: Microsoft SharePoint Server zero-day attack affects African Ministry of Finance

hacker RMM

Since November 2024, hackers have been carefully distributing specially crafted PDF documents that contain embedded links to RMM installers, effectively bypassing traditional email security measures and malware detection systems.

This attack path represents an evolution in social engineering, exploiting the inherent trust enjoyed by legitimate management tools. The campaign primarily targets critical, high-value sectors such as energy, public administration, banking services , and the construction industry across Europe.

The geographic focus on Luxembourg is particularly noteworthy, as the country's high per-capita GDP makes it an attractive target for financially motivated cybercriminals.

Instead of using mass distribution methods, the cybercriminals of this campaign demonstrate high targeting precision, leveraging PDF content tailored to specific sectors and local language variations, a fact that indicates deep knowledge of regional business practices.

See also: BeyondTrust vulnerability allows privilege escalation

Hackers gain initial access to organizations with RMM tools
Hackers gain initial access to organizations with RMM tools

The attack methodology is based on carefully crafted social engineering email messages, which either spoof legitimate business addresses or use similar domains. These messages often appear to come from senior executives of the targeted organizations, significantly increasing their credibility and effectiveness.

WithSecure analysts identified the campaign through pattern analysis in PDF metadata and delivery mechanisms, noting the systematic use of embedded direct download links pointing to official RMM provider platforms. WithSecure researchers documented a significant tactical evolution in distribution mechanisms, noting the abuse of trusted platforms like Zendesk to spread malicious PDFs .

This shift represents a calculated attempt to bypass email security filters by leveraging platforms that are typically not associated with phishing-type attacks.

See also: Hackers deploy Linux Auto-Color via SAP NetWeaver flaw

What makes this campaign special is not only its technical sophistication, but also its operational understanding: the language adaptation, imitation of internal communication, and strategic choice of platforms demonstrate that this is a threat , requiring advanced detection measures and increased personnel training.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS