Phishing Campaign Exploits LogMeIn Resolve and ScreenConnect Tools

Phishing Campaign Exploits LogMeIn Resolve and ScreenConnect Tools

First seen 7 Apr 2026, 13:19 UTC GbhackersCybersecuritynews 88% similarity 51.9

Article Content

Browse articles
ThreatCluster

Threat actors are leveraging the legitimate remote monitoring and management tools LogMeIn Resolve and ScreenConnect in a sophisticated phishing campaign. This multi-stage attack combines social engineering tactics with stealthy information-stealing malware. Sophos’ Managed Detection and Response (MDR) teams first detected this activity in April 2025, with a significant increase in malicious activity noted between October and November 2025. The campaign targets organizations primarily in the United States, aiming to bypass security defenses by using trusted software. Specific details regarding the number of affected organizations or systems have not been disclosed. The current status indicates ongoing exploitation of these tools in phishing attempts. Security professionals are advised to remain vigilant against such tactics.

Key Points: • Threat actors are exploiting LogMeIn Resolve and ScreenConnect in phishing campaigns. • The campaign blends social engineering with information-stealing malware. • Most malicious activity was observed between October and November 2025.

ThreatCluster AI

Timeline

2025-04-01
Sophos first detected the phishing campaign.
2025-10-01
Significant increase in malicious activity observed.
2025-11-30
Malicious activity peaks during this period.
2026-04-07
Articles published detailing the ongoing threat.

Community

Browse all →

Tracked Entities in This Story