Proofpoint flags cyber-enabled cargo theft surge, as hackers exploit RMM tools across ...
New research from Proofpoint reveals that cybercriminals are compromising trucking and freight companies through elaborate attack chains designed to steal cargo shipments. Cargo theft has become a multi-million-dollar criminal enterprise, fueled by the digital transformation of logistics that has opened new avenues for cyber-enabled theft. Threat actors gain access to these companies’ systems and use their credentials to fraudulently bid on cargo shipments, which they then steal and sell. In most cases, these hackers deploy remote monitoring and management (RMM) tools, reflecting a broader trend of cybercriminals adopting such software as a first-stage payload across the threat landscape.
The exploitation of RMM tools in cyber-enabled cargo theft ties into larger OT (operational technology) and IT convergence issues, as these tools are prevalent in industrial and critical infrastructure settings. These observations underscore a broader trend being seen across logistics and transportation systems, including surface transportation, with digitization resulting in new avenues of exploitation that malicious hackers are monetizing. Such threats and attacks can have implications for supply chain security, operational resilience, and cybercrime directed at tangible assets.
“Based on our ongoing investigations paired with open-source information, Proofpoint assesses with high confidence that the threat actors are working with organized crime groups to compromise entities in the surface transportation industry — in particular trucking carriers and freight brokers — to hijack cargo freight, leading to the theft of physical goods,” Ole Villadsen, Selena Larson, and the Proofpoint threat research team, wrote in a Monday blog post. “The stolen cargo most likely is sold online or shipped overseas. Such crimes can create massive disruptions to supply chains and cost companies millions, with criminals stealing everything from energy drinks to electronics.”
They added that in the observed campaigns, threat actors aim to infiltrate companies and use their fraudulent access to bid on real shipments of goods to ultimately steal them. “The observed campaigns described in this report are similar to activity Proofpoint researchers previously detailed in September 2024 . However, we cannot assess with high confidence whether historic and current campaigns are conducted by the same or multiple groups; thus, Proofpoint is not attributing the activity to a tracked threat actor.”
The threat cluster engaged in suspected cargo theft has been active since at least June 2025, though evidence suggests the group’s campaigns began as early as January. The actor has delivered a range of RMM tools (or in some cases remote access software), including ScreenConnect, SimpleHelp, PDQ Connect, Fleetdeck, N-able, and LogMeIn Resolve. These RMMs/RAS are often used in tandem; for example, PDQ Connect has been observed downloading and installing both ScreenConnect and SimpleHelp. Once initial access is established, the threat actor conducts system and network reconnaissance and deploys credential harvesting tools such as WebBrowserPassView. This activity indicates a broader effort to compromise accounts and deepen access within targeted environments.
Researchers have identified related network infrastructure and similar tactics, techniques, and procedures (TTPs) in campaigns delivering NetSupport and ScreenConnect going back to January 2025, suggesting a longer operational timeline. Separately, from 2024 through March 2025, Proofpoint also tracked a threat actor targeting ground transportation organizations distributing DanaBot, NetSupport, Lumma Stealer, and StealC.
“It is possible these clusters of activity are all related; however, we cannot attribute this with high confidence. All appear to have knowledge the software, services, and policies around how the cargo supply chain operates,” the researchers mentioned. “Regardless of the ultimate payload, stealers and RMMs serve the same purpose: remotely access the target to steal information. However, using RMM tools can enable threat actors to fly further under the radar. Threat actors can create and distribute attacker-owned remote monitoring tools, and because they are often used as legitimate pieces of software, end users might be less suspicious of installing RMMs than other remote access trojans.”
Additionally, such tooling may evade anti-virus or network detections because the installers are often signed, legitimate payloads distributed maliciously. Cargo theft actors using RMMs aligns with an overall shift in the cybercrime landscape where threat actors increasingly are adopting RMMs as a first-stage payload.
Over the last two months, Proofpoint has observed nearly two dozen campaigns, with volumes ranging from less than 10 to over 1,000 messages per campaign. It disclosed that SimpleHelp and N-able were the most frequently observed first-stage payloads since August 2025, each accounting for 38.10% of the total. ScreenConnect followed with 14.29%, while both LogMeIn Resolve and Fleetdeck made up 4.76% each.
The threat cluster has used three main tactics to deliver RMM tools. First, the actors compromise load boards by posting fraudulent freight listings using stolen accounts, then send emails with malicious URLs to carriers who inquire the loads. This approach exploits the trust and urgency typical of freight negotiations. Second, they engage in email thread hijacking, using compromised email accounts to insert malicious links and content into existing conversations.
Lastly, the cluster conducts direct email campaigns targeting larger organizations such as asset-based carriers, freight brokerage firms, and integrated supply chain providers. By gaining access to these entities, the attackers can identify high-value freight loads or find other opportunities to advance their objectives, including posting fake loads on load boards.
The researchers highlighted that typically, emails contain URLs that lead to an executable ([dot]exe) or an MSI ([dot]msi) file. When clicked, these files install an RMM tool, granting the threat actor full control of the compromised machine. In some cases, the threat actor will create domains and landing pages that impersonate legitimate brands or generic transportation terms to further the believability of the social engineering.
Based on campaigns observed by Proofpoint, the threat actor does not appear to attack specific companies, and targets range from small, family-owned businesses to large transport firms, the researchers identified. “The threat actor appears to be opportunistic the carriers that it targets and will likely attempt to compromise any carrier who responds to the fake load posting. Once a threat actor has compromised a carrier, they probably will use their knowledge of the industry and any insider information derived from other compromises to identify and bid on loads that are likely to be profitable if stolen.”
While investigating the objectives of this threat cluster, Proofpoint researchers found multiple public discussions on social media websites that aligned precisely with the phishing and account takeover activity they had observed by the actor.
One public post shared an experience in which the attacker compromised the company via RMM delivery, deleted existing bookings and blocked dispatcher notifications, added their own device to the dispatcher’s phone extension, booked loads under the compromised carrier’s name, and coordinated the transport.
To defend against RMM abuse, Proofpoint recommends several measures. Organizations should restrict the download and installation of any RMM tools that have not been approved or verified by their information technology administrators. They should also implement network detections, including the Emerging Threats ruleset, and use endpoint protection to alert security teams of any network activity connecting to RMM servers. Employees should avoid downloading or installing executable files, such as [dot]exe or [dot]msi, that are delivered via email from external senders. Finally, users should be trained to recognize and report suspicious activity to their security teams, with this training integrated into existing cybersecurity awareness programs.
In conclusion, Proofpoint has observed nearly two dozen campaigns since August this year targeting such entities to deliver RMMs. Public discussion and reporting on cyber-enabled cargo theft suggest the problem is widespread, impacting organizations nationwide, and only increasing in scope and spread. Based on the growth of this activity in email threat data between 2024 and 2025, Proofpoint assesses that this threat will continue to increase. Organizations should be aware of the cyber-enabled tactics and payloads used by cargo theft criminals and implement cybersecurity measures to prevent successful exploitation.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
