LogMeIn is a tool tracked across 10 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity February 19, 2026.
LogMeIn is a legitimate remote access and remote management tool used for IT support and remote monitoring. In recent campaigns, threat actors have abused LogMeIn (along with PDQ Connect) as RMM tools to disguise malware as legitimate software, enabling stealthy deployment and persistence while evading detection.
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…
Cybercriminals created a fake remote management vendor that sells a remote access trojan (RAT) disguised as legitimate enterprise software for $300 a month. This scheme exploits the growing trend of using remote…
Recent attacks have been identified that exploit the Remote Monitoring and Management tools LogMeIn Resolve and PDQ Connect. Cybercriminals are using a legitimate-looking website to disguise malware as normal software,…
A Qilin ransomware incident has prompted a detailed investigation by security analysts. The analysis focuses on understanding how attackers gained initial access and the subsequent actions taken, using various clues…
Cybersecurity experts have identified malware distribution cases that exploit the RMM tools LogMeIn Resolve and PDQ Connect. The malware is disguised as legitimate software on a seemingly normal website, leading users…
In 2025, there has been a significant rise in the abuse of ScreenConnect and other remote monitoring and management (RMM) tools by threat actors. Organizations using outdated or unpatched versions of these tools are…
A phishing campaign has been identified that leverages stolen credentials and legitimate remote monitoring and management (RMM) software to gain persistent access to corporate systems. Attackers initiate the campaign…
A Qilin ransomware attack has prompted an investigation by security analysts to determine how the attackers gained initial access and the subsequent actions taken. The analysis involves examining logs, antivirus…
Recent attacks have been identified exploiting Remote Monitoring and Management tools LogMeIn Resolve and PDQ Connect. Cyberattackers are distributing malware disguised as legitimate software through a seemingly normal…