RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)
In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited.
RMM (Remote Monitoring and Management) tools are not malware such as backdoors or RATs, but they allow remote control of installed systems and are used by organizations for legitimate purposes; as a result, various threat actors are exploiting them. This is done intentionally to bypass detection by security products; unlike typical malware, security products such as firewalls and antivirus software have limitations when it comes to simply detecting and blocking such tools.
Attack cases involving the distribution of such RMM tools continue to this day, and recently, tools such as FleetDeck, Datto, SimpleHelp, JumpCloud, and N-able have been exploited. Here, we disclose recently identified cases of RMM tool distribution.
1. ScreenConnect
Although ConnectWise ScreenConnect has been covered in past reports, it remains the most widely distributed type to date. In addition to the attack cases discussed here that exploit Attachments in phishing emails, APT and ransomware threat actors have also used ScreenConnect. In the second half of 2026, ScreenConnect was distributed in various forms, such as LNK, BAT, and VBS files; based on the file names, it is presumed that these were primarily attachments to phishing emails.

Figure 1. Decoy document file used in the distribution of ScreenConnect via LNK malware
- Dropbox.SharedfilePDF.LNK
- ZoomSetup-V.7.3.Bat
- Wire Receipt Form_pdf.Vbs
ScreenConnect supports functions such as RMM (Remote Management and Monitoring), remote support, and IT asset management, providing remote access and screen control capabilities. The C2 server and port number information for ScreenConnect can be identified in the execution arguments as follows.

Figure 2. Process tree during ScreenConnect installation
2. FleetDeck
Recently, instances of FleetDeck distribution have also been identified; FleetDeck was previously used by the “Scattered Spider” threat actors who distributed the DragonForce ransomware. [3] The identified instances of FleetDeck distribution exploited PDF documents; users were tricked into clicking a link to view an Attachment that appeared to be a document, and clicking the link resulted in the download of the FleetDeck executable file.

Figure 3. PDF document file distributing FleetDeck
The downloaded file is a FleetDeck installer. A distinctive feature of FleetDeck is that deployment ID information is embedded at the end of the file. During installation, this ID is passed as the “-deploymentID” argument, allowing the threat actor who distributed it to take control.

Figure 4. Deployment ID present in the FleetDeck installation file
> “C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent_svc.Exe” -deploymentID c99d93d7-68f9-4baa-bc21-2aa2097de3be -askForName=0
3. Datto
Datto RMM is also a cloud-based RMM solution that allows MSPs or IT administrators to install an agent on remote systems to perform endpoint monitoring, remote control, patch management, and executing a script. Like FleetDeck, it was distributed through a PDF document, which displays a Figure prompting the user to update Adobe Acrobat Pro to view the document. However, the EXE file “AdrAcroPro11.2_3D_client.Exe” that is actually downloaded when the link is clicked is Datto RMM.

Figure 5. PDF document used to distribute Datto RMM
Datto stores configuration information in the “CagService.Exe.Config” configuration file located inside the installation package. Given that Channel Insider reported the “AccountUid” configuration information within this file to Kaseya, Datto’s parent company, it is presumed that the “AccountUid” value serves as the threat actor’s unique identifier. [4]

Figure 6. Configuration information for Datto RMM exploited in the attack
4. SimpleHelp
SimpleHelp is a solution for remote support and system management that provides features such as remote control, monitoring, and executing a script. Cases where threat actors exploit such features to gain remote control over infected systems continue to be identified; SimpleHelp has been used in attacks linked to the Play [5] ransomware, as well as in Medusa [6] and ALPHV (BlackCat) [7] ransomware attacks.

Figure 7. HTML phishing script distributing SimpleHelp
SimpleHelp contains configuration information within the file, and the C&C server address is stored as a hex value in the “sg_servers” entry. [8]

Figure 8. SimpleHelp configuration information stored as hex data
5. JumpCloud
JumpCloud is a cloud-based device management solution that enables unified management of user accounts and endpoints, as well as remote command execution. Although there are not many known cases of exploitation, [9] a recent case was identified in which it was distributed through a phishing page that disguised itself as an Adobe security document. Clicking the “Download Document” button on a phishing page like the one as follows downloads a batch malware file that installs JumpCloud. Note that the same site also hosts a phishing page distributing FleetDeck in addition to JumpCloud.

Figure 9. HTML phishing page distributing JumpCloud
The “Batch” malware installs JumpCloud by downloading and executing it, specifying the threat actor’s key value as the “CONNECT_KEY” argument value.

Figure 10. PCloud installation script
6. N-able
N-able is an RMM solution that provides endpoint monitoring, patch management, remote access, and the ability to execute a script. Recently, cases of N-able being exploited have also been identified. The following example is a Batch malware sample that disguises itself as DocuSign Viewer; to deceive users, it displays a Support page in the web browser alongside the N-able installation when executed.

Figure 11. N-able installation malware and redirect page
The “settings.Ini” file inside the N-able installer contains the threat actor’s email address, “mark@hessattorneys.Co[.]Za,” as shown below. Note that accessing the email address “hessattorneys.Co[.]Za” via a web browser displays a page that is disguised as DocuSign; if the user clicks to view a document, a message appears stating that a viewer is required. In other words, it is presumed that the threat actor uses such a phishing page to trick users into installing N-able, which is disguised as a document viewer.

Figure 12. N-able configuration file

Figure 13. Page disguised as DocuSign
7. Conclusion
Users must exercise extreme caution when opening emails from unknown sources. Verify that the sender is trustworthy, and if the email prompts you to click a link in an Attachment, check the linked URL carefully before clicking. Suspicious URLs often redirect to legitimate pages via intermediate paths rather than going directly to the official site, so they must be examined carefully. Additionally, if there are attachments, check for suspicious file extensions (.Exe, .Com, etc.). You should also keep your operating system and security software updated to the latest versions to protect against known threats.