Skip to content
Phishing Campaign Exploits LogMeIn Resolve and ScreenConnect Tools

Phishing Campaign Exploits LogMeIn Resolve and ScreenConnect Tools

First seen 7 Apr 2026, 13:19 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 8, 2026 at 13:04 UTC
  • Threat actors are exploiting LogMeIn Resolve and ScreenConnect in phishing campaigns.
  • The campaign blends social engineering with information-stealing malware.
  • Most malicious activity was observed between October and November 2025.

Threat actors are leveraging the legitimate remote monitoring and management tools LogMeIn Resolve and ScreenConnect in a sophisticated phishing campaign. This multi-stage attack combines social engineering tactics with stealthy information-stealing malware. Sophos’ Managed Detection and Response (MDR) teams first detected this activity in April 2025, with a significant increase in malicious activity noted between October and November 2025. The campaign targets organizations primarily in the United States, aiming to bypass security defenses by using trusted software. Specific details regarding the number of affected organizations or systems have not been disclosed. The current status indicates ongoing exploitation of these tools in phishing attempts. Security professionals are advised to remain vigilant against such tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 156d ago How this analysis works

Timeline

2025-04-01
Sophos first detected the phishing campaign.
2025-10-01
Significant increase in malicious activity observed.
2025-11-30
Malicious activity peaks during this period.
2026-04-07
Articles published detailing the ongoing threat.

More articles in this cluster (2)