Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-impersonation-fraudremote-access-implantdefense-evasion-method

Phishing Campaigns Weaponize Legitimate RMM Tools for Remote Access and Credential Theft

Updated 3mo agoFirst seen Feb 18, 20262 sources

Threat researchers reported multiple phishing-driven intrusions in which attackers impersonate trusted brands and agencies to trick victims into installing legitimate remote monitoring and management (RMM) software for persistent access. In Operation DoppelBrand, financially motivated actor GS7 spoofed Fortune 500 financial and technology brands (including Wells Fargo and USAA) using more than 150 lookalike domains to harvest credentials and exfiltrate data via attacker-controlled Telegram bots; researchers also identified nearly 200 additional domains with short registration terms, automated SSL, wildcard DNS, and brand-specific subdomains supporting the campaign.

Separately, Forcepoint X-Labs described a wave of emails impersonating the U.S. Social Security Administration that delivers an attached .cmd script to weaken Windows defenses and enable silent installation of ConnectWise ScreenConnect. The script checks/elevates privileges, disables Windows SmartScreen via registry changes, removes Mark-of-the-Web, and uses Alternate Data Streams (ADS) for stealth before installing an MSI and configuring ScreenConnect (via System.config) to beacon to an attacker-controlled server (reported as dof-connecttop on port 8041). Both activity sets highlight a recurring tradecraft pattern: brand impersonation + scripted defense evasion + abuse of legitimate RMM tooling (e.g., LogMeIn Resolve, ScreenConnect) to gain remote control and facilitate follow-on theft or persistence.

Share:
Phishing Campaigns Weaponize Legitimate RMM Tools for Remote Access and Credential Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 18, 20264mo ago

SOCRadar attributes Doppelbrand to threat actor GS7

SOCRadar attributed Operation Doppelbrand to a financially motivated threat actor tracked as GS7 and assessed the campaign's automated infrastructure, brand impersonation, and RMM abuse as especially dangerous. The findings were publicly reported after the campaign's December 2025 to January 2026 activity window.

Feb 17, 20264mo ago

Researchers link ScreenConnect campaign to Iranian network infrastructure

Analysis of the ScreenConnect campaign found the installed client configured to call back on port 8041 to infrastructure associated with the Aria Shatel Company Ltd network in Iran. Researchers also noted use of ScreenConnect version 25.2.4.9229 signed with a revoked certificate.

Forcepoint observes ScreenConnect phishing campaign using SSA lures

Forcepoint X-Labs reported a wave of attacks targeting organizations in the UK, US, Canada, and Northern Ireland with phishing emails impersonating the U.S. Social Security Administration. The emails carried malicious .cmd attachments that weakened Windows protections, disabled SmartScreen, removed Mark-of-the-Web protections, and then installed ConnectWise ScreenConnect for persistent remote access.

Jan 31, 20265mo ago

Attackers run Doppelbrand through January with broad phishing infrastructure

Through January 2026, the Doppelbrand campaign continued using more than 150 lookalike domains and delivered legitimate RMM tools such as LogMeIn Resolve, along with MSI installers and VBS loaders for stealthy installation, privilege escalation, and persistence. Researchers later identified roughly 200 additional related domains sharing common registration and DNS patterns.

Dec 1, 20257mo ago

Operation Doppelbrand begins spoofing Fortune 500 brands

A phishing campaign later dubbed Operation Doppelbrand began in December 2025, impersonating major financial, technology, and insurance brands including Wells Fargo and USAA. The operation used lookalike domains to harvest credentials and exfiltrate stolen data through attacker-controlled Telegram bots.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
TelegramWindowsWindows Explorer
Organizations
10 linked
Wells FargoSOCRadarInfosecurity MagazineUsaaLogmeinFortune MediaForcepointConnectwiseHackread.comAria Shatel Company Ltd
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Campaigns Weaponize Legitimate RMM Tools for Remote Access and Credential Theft | Mallory