Signed Malware Deploys RMM Backdoors via Phishing Campaigns

Signed Malware Deploys RMM Backdoors via Phishing Campaigns

First seen 5 Mar 2026, 17:11 UTC Blogs.MicrosoftRedmondmagCybersecuritynewsGbhackersCyberpress 83% similarity 63.8

Article Content

Browse articles
ThreatCluster

Microsoft's Defender Security Research Team reported phishing campaigns utilizing signed malware disguised as workplace applications. This malware, backed by a stolen EV certificate, installs remote monitoring and management (RMM) tools to maintain persistent access within enterprise environments, posing a significant risk to organizations. Enhanced certificate controls and monitoring of RMM activity are recommended to mitigate exposure.

ThreatCluster AI

Timeline

2026-03-03
Microsoft blog post details signed malware deployment
2026-03-05
Redmondmag article reports on phishing campaigns

Community

Browse all →

Tracked Entities in This Story