LogMeIn - Tool

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
November 13, 2025
Last Seen
February 19, 2026

LogMeIn is a tool tracked across 10 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity February 19, 2026.

Overview

LogMeIn is a legitimate remote access and remote management tool used for IT support and remote monitoring. In recent campaigns, threat actors have abused LogMeIn (along with PDQ Connect) as RMM tools to disguise malware as legitimate software, enabling stealthy deployment and persistence while evading detection.

Related Threat Clusters

  • Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million

    The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…

    9 articles · Updated November 14, 2025
  • Microsoft Mitigates Windows LNK Vulnerability Exploited in Zero-Day Attacks

    Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…

    3 articles · Updated December 3, 2025
  • Criminals Launch RAT-as-a-Service via Fake RMM Vendor

    Cybercriminals created a fake remote management vendor that sells a remote access trojan (RAT) disguised as legitimate enterprise software for $300 a month. This scheme exploits the growing trend of using remote…

    7 articles · Updated February 19, 2026
  • Malware Distribution via LogMeIn and PDQ Connect RMM Tools Identified

    Recent attacks have been identified that exploit the Remote Monitoring and Management tools LogMeIn Resolve and PDQ Connect. Cybercriminals are using a legitimate-looking website to disguise malware as normal software,…

    1 article · Updated November 13, 2025
  • Investigation into Qilin Ransomware Incident

    A Qilin ransomware incident has prompted a detailed investigation by security analysts. The analysis focuses on understanding how attackers gained initial access and the subsequent actions taken, using various clues…

    2 articles · Updated November 22, 2025
  • Malware Distributed via LogMeIn and PDQ Connect Exploits

    Cybersecurity experts have identified malware distribution cases that exploit the RMM tools LogMeIn Resolve and PDQ Connect. The malware is disguised as legitimate software on a seemingly normal website, leading users…

    2 articles · Updated November 13, 2025
  • Increased Abuse of ScreenConnect by Threat Actors in 2025

    In 2025, there has been a significant rise in the abuse of ScreenConnect and other remote monitoring and management (RMM) tools by threat actors. Organizations using outdated or unpatched versions of these tools are…

    2 articles · Updated December 31, 2025
  • Phishing Campaign Uses RMM Tools for Stealthy Corporate Access

    A phishing campaign has been identified that leverages stolen credentials and legitimate remote monitoring and management (RMM) software to gain persistent access to corporate systems. Attackers initiate the campaign…

    2 articles · Updated January 23, 2026
  • Investigation into Qilin Ransomware Incident

    A Qilin ransomware attack has prompted an investigation by security analysts to determine how the attackers gained initial access and the subsequent actions taken. The analysis involves examining logs, antivirus…

    2 articles · Updated November 22, 2025
  • Malware Distribution via LogMeIn and PDQ Connect RMM Tools

    Recent attacks have been identified exploiting Remote Monitoring and Management tools LogMeIn Resolve and PDQ Connect. Cyberattackers are distributing malware disguised as legitimate software through a seemingly normal…

    3 articles · Updated November 13, 2025

Recent Intelligence Reports

  • (Don't) TrustConnect: It's a RAT in an RMM hat — Proofpoint · February 19, 2026
  • Phishing campaign exploits RMM tools for stealthy access — Securitybrief.Au · January 23, 2026
  • Phishing campaign exploits RMM tools for stealthy access — Itbrief · January 23, 2026
  • Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025 — Huntress · December 31, 2025
  • Windows LNK Vulnerabilities: Unpatched Flaws Exploited by Hackers Since 2017 — Webpronews · November 24, 2025
  • Piecing Together the Puzzle: A Qilin Ransomware Investigation — Bleepingcomputer · November 22, 2025
  • Akira actively engaged in ransomware attacks against critical sectors — Cybersecuritydive · November 13, 2025
  • FBI calls Akira ‘top five’ ransomware variant out of 130 targeting US businesses — Cyberscoop · November 13, 2025

CVSS v3.1 Breakdown