Skip to content
Signed Malware Deploys RMM Backdoors via Phishing Campaigns

Signed Malware Deploys RMM Backdoors via Phishing Campaigns

First seen 5 Mar 2026, 17:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Microsoft's Defender Security Research Team reported phishing campaigns utilizing signed malware disguised as workplace applications. This malware, backed by a stolen EV certificate, installs remote monitoring and management (RMM) tools to maintain persistent access within enterprise environments, posing a significant risk to organizations. Enhanced certificate controls and monitoring of RMM activity are recommended to mitigate exposure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-03-03
Microsoft blog post details signed malware deployment
2026-03-05
Redmondmag article reports on phishing campaigns

More articles in this cluster (5)