Skip to content
Signed malware impersonating workplace apps deploys RMM backdoors

Signed malware impersonating workplace apps deploys RMM backdoors

Blogs.Microsoft Microsoft Defender Security Research Team March 3, 2026

Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure.

Extracted Entities

Attack Types (1)

Tools (1)