HomeSecurityHackers exploit RMM tools to penetrate Logistics networks

Hackers exploit RMM tools to penetrate Logistics networks

Malicious actors are increasingly targeting trucking and logistics companies to infect them with software remote monitoring and management . The goal is financial gain and cargo theft.

Hackers RMM Logistics

This threat complex, believed to have been active since at least June 2025 according to Proofpoint, works with organized crime groups to infiltrate entities in the transportation industry (with the goal of stealing physical goods). The most targeted products in these cyber-physical heists are food and beverages.

See also: NPM Breach: New Business Email Protection Technique

“The stolen cargo is likely sold online or shipped overseas,” said researchers Ole Villadsen and Selena Larson. “In the observed campaigns, threat actors infiltrate companies and use their access to bid on actual shipments of goods to ultimately steal them.”

The current wave of infiltrations, detected by Proofpoint, shows that unknown attackers have used multiple methods, including compromised email accounts to take over existing conversations, spear-phishing emails , and fake payload listings using compromised accounts in payload boards.

Hackers exploit RMM tools to penetrate Logistics networks

The malicious URLs embedded in the messages lead to MSI installers or executables that deploy legitimate RMM tools such as ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve. In some cases, several of these programs are used together, with PDQ Connect being used to install ScreenConnect and SimpleHelp.

See also: Hackers distribute SSH-Tor Backdoor via military documents

Once remote access, attackers conduct system and network reconnaissance. This is followed by deployment of credential harvesting tools, such as WebBrowserPassView, to capture additional credentials and penetrate the corporate network.

In at least one case, the threat actor appears to have used the access to delete existing reservations and block sender notifications.

Hackers exploit RMM tools to penetrate Logistics networks

Abuse of RMM software to breach Logistics

Using RMM software offers several advantages. First, it eliminates the need for threat actors to create custom malware. Second, it allows them to operate stealthily, as these tools are prevalent in corporate environments and are typically not flagged as malicious by security solutions.

See also: New HttpTroy backdoor disguises itself as a VPN invoice

“It is quite easy for threat actors to create and distribute remote monitoring tools, and because they are often disguised as legitimate software, end users are less suspicious,” Proofpoint noted in March 2025. “Furthermore, such tools can evade detection by anti-virus or networks because the installers are often signed, meaning they are legitimate payloads distributed maliciously.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS