Redmondmag
Signed Malware Deploys RMM Backdoors via Phishing Campaigns
First seen 5 Mar 2026, 17:11 UTC
•



•83% similarity
•63.8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Microsoft's Defender Security Research Team reported phishing campaigns utilizing signed malware disguised as workplace applications. This malware, backed by a stolen EV certificate, installs remote monitoring and management (RMM) tools to maintain persistent access within enterprise environments, posing a significant risk to organizations. Enhanced certificate controls and monitoring of RMM activity are recommended to mitigate exposure.
ThreatCluster AI
Timeline
2026-03-03
Microsoft blog post details signed malware deployment
2026-03-05
Redmondmag article reports on phishing campaigns