#NSBCS.139 - From Inbox to Endpoint: How RMM Tools Are Reshaping Phishing Campaigns
Background
Phishing campaigns have traditionally focused on credential theft, with threat actors leveraging fake login pages to harvest user credentials and gain unauthorised access to email accounts. However, we have increasingly seen in recent incidents an alternative approach: rather than attempting to compromise credentials directly, threat actors are leveraging legitimate remote monitoring and management (RMM) tools to obtain remote access to users' devices. Tools such as ScreenConnect or AnyDesk are designed to provide legitimate remote support capabilities, but these same capabilities provide a lucrative exploit for threat actors to leverage.
This approach aligns with the broader concept of Living off the Land (LOTL), whereby threat actors leverage legitimate and trusted tools or system functionality to conduct malicious activity. As RMM tools are commonly used by IT administrators and managed service providers (MSPs), their presence and associated activity may appear legitimate and can be more difficult to distinguish from normal administrative behaviour. By abusing these tools, threat actors can obtain extensive remote control over a compromised device while reducing their reliance on traditional malware, potentially allowing their activity to evade or delay detection by existing security controls.
Attack Overview
Recent attack chains we have observed start with a convincing phishing email that imitates an everyday business interaction, such as a shared document, Microsoft Teams notification or meeting transcript. Rather than directing the victim to a traditional credential harvesting page, the phishing infrastructure encourages the user to download and execute what appears to be a legitimate file or application. In a recent incident we investigated, this interaction ultimately resulted in a ScreenConnect client being installed on the affected workstation. The threat actor subsequently leveraged legitimate Windows utilities, including PowerShell, to facilitate the installation and conceal the remote access software from the standard Windows installed applications list.
Figure 1: Illegitimate Microsoft Teams Screen Capture
This approach presents a different challenge for organisations because successful compromise may not require the threat actor obtaining the user's credentials or bypassing multi-factor authentication (MFA). Once remote control of an endpoint has been established, the threat actor may inherit access to applications and browser sessions that are already authenticated on that device. Email, cloud storage and other business applications may therefore become accessible through the user's existing sessions.
Reducing the Risk
Defending against RMM-based phishing campaigns requires organisations to look beyond traditional email and identity security, as the objective may be to compromise the endpoint rather than the user's credentials. A combination of preventative controls, endpoint visibility and user awareness can help reduce the likelihood and impact of these attacks.
Organisations should consider the following measures:
Restrict unauthorised RMM tools: Implement application control to prevent unapproved remote access software such as ScreenConnect or AnyDesk from being installed or executed. Where RMM tools are required, consider allow listing only approved solutions.
Review endpoint security: Ensure Endpoint Detection and Response (EDR) solutions provide appropriate behavioural detection, alerting and sufficient historical telemetry to identify and investigate suspicious process, network and remote-access activity.
Implement appropriate session controls: Configure cloud session and re-authentication policies to reduce the period that authenticated sessions remain accessible, particularly following the compromise of an endpoint.
Strengthen security awareness: Educate users to be cautious of unexpected document-sharing notifications, meeting invitations, software downloads and requests to install remote support tools.
As threat actors continue to adapt legitimate tools and everyday business processes for malicious purposes, proactive security reviews can help organisations identify gaps before they are exposed during an incident. Assessing endpoint and cloud security controls against current attack techniques can provide organisations with a clearer understanding of their security posture and practical opportunities for improvement.
If your organisation is considering a cyber security review or would like greater assurance that its existing controls are prepared for evolving threats, please feel free to reach out to our team to discuss how our security services can assist.
What we read this week
ACSC Warns of Active Exploitation of Critical TeamCity On-Premises Flaw Targeting Australian Organisations - The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has observed active exploitation of CVE-2026-63077 within Australia. The critical remote code execution vulnerability in JetBrains TeamCity On-Premises allows an unauthenticated attacker with HTTP(S) access to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. All On-Premises versions are affected. JetBrains released fixes in versions 2025.11.7 and 2026.1.3, plus a security patch plugin. The ACSC advises organisations to review networks for vulnerable instances, remove unnecessary internet exposure of the interface, apply updates immediately, and contact managed service providers if the platform is outsourced. No specific industry or sector has been identified as targeted.
Storm Ransomware Group Claims Breach of Westco Motors Cairns - The newly emerged Storm ransomware group has listed Westco Motors Cairns, a prestige multi-franchise car dealership in Tropical North Queensland, as a victim. Sample documents allegedly stolen, including customer invoices, vehicle identification numbers, tax invoices and contact details (email addresses and mobile numbers), were published on the group’s dark-web leak site. Storm emerged earlier this month and has already claimed three Australian victims. The dealership has not publicly confirmed the incident. Organisations, particularly mid-market and regional businesses, should prioritise offline backups, multi-factor authentication, email security controls and dark-web monitoring for early detection of extortion claims.
Interpol Operation Jackal IV Nets 58 Arrests Across 22 Countries, Including Australia - Interpol-coordinated Operation Jackal IV, running from November 2025 to June 2026, has resulted in 58 arrests and the identification of 263 suspects linked to West African organised cyber-crime networks. Australia was one of 22 participating countries across six continents. The operation targeted groups responsible for a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise, as well as emerging trends such as sextortion of minors. Assets including cash, cryptocurrency, properties and luxury goods were seized. The action highlights the value of international intelligence sharing against transnational cyber-enabled fraud networks.
FBI and DOJ Disrupt China-Linked QTFY Hacking Platforms Used Against US Critical Infrastructure - The US Department of Justice and FBI seized domains supporting the QScan scanning/exploitation platform and QTRouter obfuscation network operated by the China state-sponsored group QTFY (linked to Nanjing Xinjiuwei Network Technology Company). The tools enabled reconnaissance, proxy management and operational relay capabilities used against US critical infrastructure and sensitive networks, including NASA, the Federal Reserve, the US Senate and multiple federal departments. Compromised IoT devices and commercial proxies were used to conceal the origin of traffic. Domain seizures rendered the hard-coded infrastructure inoperable. Organisations should review historical logs for related indicators and strengthen monitoring of IoT and proxy traffic.
NovaCookies Adversary-in-the-Middle Service Steals Microsoft 365 Sessions for $320 a Month - Researchers at Island detailed NovaCookies, a commercial phishing-as-a-service platform that relays Microsoft 365 sign-ins in real time to capture authenticated session cookies, bypassing multifactor authentication. Advertised at approximately $320 per month, the service supplies lures, domains, hosting and support. Campaigns have targeted hundreds of organisations across multiple countries, including Australia-relevant regions, with at least 755 dedicated malicious domains identified. Delivery has included genuine DocuSign notifications carrying counterfeit document-share lures. Organisations should prioritise phishing-resistant MFA (such as FIDO2/passkeys), session monitoring and user education on unexpected document-sharing requests.
References

