RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited. RMM (Remote Monitoring and

ConnectWise Product Security Update Advisory (CVE-2026-84869)

ConnectWise Product Security Update Advisory (CVE-2026-84869)

Overview A security update has been released to address a vulnerability in a ConnectWise product. The affected product is ConnectWise ScreenConnect, and versions prior to 26.6.5 Are vulnerable. Vulnerability Details The CVE-2026-84869 vulnerability was identified in the ConnectWise ScreenConnect client. This vulnerability is described as an issue that allows files

Beware of Phishing Emails Disguised as Transaction Receipts

Beware of Phishing Emails Disguised as Transaction Receipts

Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds

Detection of Recent RMM Distribution Cases Using AhnLab EDR

Detection of Recent RMM Distribution Cases Using AhnLab EDR

AhnLab SEcurity intelligence Center (ASEC) has recently observed an increase in attack cases exploiting Remote Monitoring and Management (RMM) tools. Whereas attackers previously exploited remote control tools during the process of seizing control after initial penetration, they now increasingly leverage RMM tools even during the initial distribution phase across diverse

RMM Tools (Syncro, SuperOps, NinjaOne, etc.) Being Distributed Disguised as Video Files

RMM Tools (Syncro, SuperOps, NinjaOne, etc.) Being Distributed Disguised as Video Files

AhnLab SEcurity intelligence Center (ASEC) recently discovered cases of attacks using RMM tools such as Syncro, SuperOps, NinjaOne, and ScreenConnect. Threat actors distributed a PDF file that prompted users to download and run the RMM tool from a disguised distribution page such as Google Drive. The certificate used to sign

ConnectWise ScreenConnect Security Update Advisory (CVE-2025-14265)

ConnectWise ScreenConnect Security Update Advisory (CVE-2025-14265)

Overview   We have released a security update to address a vulnerability in ConnectWise ScreenConnect. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-14265   ConnectWise ScreenConnect version: 25.less than 8     Resolved Vulnerabilities   Integrity Unvalidated Code Download Vulnerability in

Infected Systems Controlled Through Remote Administration Tools – Detected by EDR (2)

Infected Systems Controlled Through Remote Administration Tools – Detected by EDR (2)

Remote administration tools, also known as RAT, are software that provide the ability to manage and control terminals at remote locations. Recently, there has been an increase in cases where remote administration tools are installed instead of backdoor malware during the initial access or lateral movement phases to control the