RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited.

RMM (Remote Monitoring and Management) tools are not malware such as backdoors or RATs, but they allow remote control of installed systems and are used by organizations for legitimate purposes; as a result, various threat actors are exploiting them. This is done intentionally to bypass detection by security products; unlike typical malware, security products such as firewalls and antivirus software have limitations when it comes to simply detecting and blocking such tools.

Attack cases involving the distribution of such RMM tools continue to this day, and recently, tools such as FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able have been exploited. Here, we disclose recently identified cases of RMM tool distribution.

 

1. ScreenConnect

Although ConnectWise ScreenConnect has been covered in past reports, it remains the most widely distributed type to date. In addition to the attack cases discussed here that exploit Attachments in phishing emails, APT and ransomware threat actors have also used ScreenConnect. In the second half of 2026, ScreenConnect was distributed in various forms, such as LNK, BAT, and VBS files; based on the file names, it is presumed that these were primarily attachments to phishing emails.

Figure 1. Decoy document file used in the distribution of ScreenConnect via LNK malware

  • Dropbox.SharedfilePDF.LNK
  • ZoomSetup-V.7.3.Bat
  • Wire Receipt Form_pdf.Vbs

ScreenConnect supports functions such as RMM (Remote Management and Monitoring), remote support, and IT asset management, providing remote access and screen control capabilities. The C2 server and port number information for ScreenConnect can be identified in the execution arguments as follows.

Figure 2. Process tree during ScreenConnect installation

 

2. FleetDeck

Recently, instances of FleetDeck distribution have also been identified; FleetDeck was previously used by the “Scattered Spider” threat actors who distributed the DragonForce ransomware. [3] The identified instances of FleetDeck distribution exploited PDF documents; users were tricked into clicking a link to view an Attachment that appeared to be a document, and clicking the link resulted in the download of the FleetDeck executable file.

Figure 3. PDF document file distributing FleetDeck

The downloaded file is a FleetDeck installer. A distinctive feature of FleetDeck is that deployment ID information is embedded at the end of the file. During installation, this ID is passed as the “-deploymentID” argument, allowing the threat actor who distributed it to take control.

Figure 4. Deployment ID present in the FleetDeck installation file

> “C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent_svc.Exe” -deploymentID c99d93d7-68f9-4baa-bc21-2aa2097de3be -askForName=0

 

3. Datto

Datto RMM is also a cloud-based RMM solution that allows MSPs or IT administrators to install an agent on remote systems to perform endpoint monitoring, remote control, patch management, and executing a script. Like FleetDeck, it was distributed through a PDF document, which displays a Figure prompting the user to update Adobe Acrobat Pro to view the document. However, the EXE file “AdrAcroPro11.2_3D_client.Exe” that is actually downloaded when the link is clicked is Datto RMM.

Figure 5. PDF document used to distribute Datto RMM

Datto stores configuration information in the “CagService.Exe.Config” configuration file located inside the installation package. Given that Channel Insider reported the “AccountUid” configuration information within this file to Kaseya, Datto’s parent company, it is presumed that the “AccountUid” value serves as the threat actor’s unique identifier. [4]

Figure 6. Configuration information for Datto RMM exploited in the attack

 

4. SimpleHelp

SimpleHelp is a solution for remote support and system management that provides features such as remote control, monitoring, and executing a script. Cases where threat actors exploit such features to gain remote control over infected systems continue to be identified; SimpleHelp has been used in attacks linked to the Play [5] ransomware, as well as in Medusa [6] and ALPHV (BlackCat) [7] ransomware attacks.

Figure 7. HTML phishing script distributing SimpleHelp

SimpleHelp contains configuration information within the file, and the C&C server address is stored as a hex value in the “sg_servers” entry. [8]

Figure 8. SimpleHelp configuration information stored as hex data

 

5. JumpCloud

JumpCloud is a cloud-based device management solution that enables unified management of user accounts and endpoints, as well as remote command execution. Although there are not many known cases of exploitation, [9] a recent case was identified in which it was distributed through a phishing page that disguised itself as an Adobe security document. Clicking the “Download Document” button on a phishing page like the one as follows downloads a batch malware file that installs JumpCloud. Note that the same site also hosts a phishing page distributing FleetDeck in addition to JumpCloud.

Figure 9. HTML phishing page distributing JumpCloud

The “Batch” malware installs JumpCloud by downloading and executing it, specifying the threat actor’s key value as the “CONNECT_KEY” argument value.

Figure 10. PCloud installation script

 

6. N-able

N-able is an RMM solution that provides endpoint monitoring, patch management, remote access, and the ability to execute a script. Recently, cases of N-able being exploited have also been identified. The following example is a Batch malware sample that disguises itself as DocuSign Viewer; to deceive users, it displays a Support page in the web browser alongside the N-able installation when executed. 

Figure 11. N-able installation malware and redirect page

The “settings.Ini” file inside the N-able installer contains the threat actor’s email address, “mark@hessattorneys.Co[.]Za,” as shown below. Note that accessing the email address “hessattorneys.Co[.]Za” via a web browser displays a page that is disguised as DocuSign; if the user clicks to view a document, a message appears stating that a viewer is required. In other words, it is presumed that the threat actor uses such a phishing page to trick users into installing N-able, which is disguised as a document viewer. 

Figure 12. N-able configuration file

Figure 13. Page disguised as DocuSign

 

7. Conclusion

Users must exercise extreme caution when opening emails from unknown sources. Verify that the sender is trustworthy, and if the email prompts you to click a link in an Attachment, check the linked URL carefully before clicking. Suspicious URLs often redirect to legitimate pages via intermediate paths rather than going directly to the official site, so they must be examined carefully. Additionally, if there are attachments, check for suspicious file extensions (.Exe, .Com, etc.). You should also keep your operating system and security software updated to the latest versions to protect against known threats. 

 

MD5

1017a75cf19be75f6ba21148a9b646d1
1562d523c2ebdc19c0ff8f3ea5f3763b
594a652263e5e4eb96b5164d337bc1ca
5a49d0b22ced22f9cf8b2015a327f163
5ac7526b582d9cf4f7854c52ee75f359
URL

http[:]//216[.]250[.]252[.]58[:]8040/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest
https[:]//178-83-121-6[.]cprapid[.]com/ReceiptDoc[.]vbs
https[:]//admin[.]lukiku[.]lol/Bin/ScreenConnect[.]ClientSetup[.]msi?e=Access&y=Guest
https[:]//adobpro3d[.]s[.]gy/X334zpo8tl
https[:]//bigsundoc[.]online/fold/package/
FQDN

alertxen[.]store
bigsundoc[.]online
ddncsoso[.]com
hessattorneys[.]co[.]za
relay[.]lukiku[.]lol
IP

86[.]106[.]143[.]132

Gain access to related IOCs and detailed analysis by subscribing to AhnLab TIP. For subscription details, click the banner below.