High

CA-A-26-032: Abuse of Legitimate RMM Tooling, Malicious Extensions and Session Hijacking via Internal Phishing

By Adversary Tactics and Intelligence Team

Estimated Reading Time: 5 minutes

RMM Abuse, Session Hijacking, Identity Compromise, BEC, Internal Phishing, Browser Extensions

Source Material: CISA | Hacker News | Technology: Remote Monitoring and Management | Targeted Industries: Opportunistic

Executive Summary

The Deepwatch Adversary Tactics & Intelligence team has recently observed an increase in incidents involving credential compromise, session hijacking, and RMM utility abuse across sectors. The threat actors use techniques to gain unauthorized access to internal identities, alter MFA registration devices, modify/view payroll deposit details, and systematically access sensitive HR/PII documents housed within HR and administrative tools.To expand their access and establish persistent footholds, the threat actors utilize compromised internal identities to distribute internal phishing communications. These emails entice internal recipients to download and execute legitimate Remote Monitoring and Management (RMM) applications, using authorized system administration software as covert Command and Control channels. Attackers are also observed utilizing phone, chat, and internal email impersonation to trick help desk teams into resetting passwords, MFA, granting unauthorized access, or installing remote software under the guise of urgent IT support.

Investigations revealed that affected users experienced abnormal login session disruptions prior to account takeover, strongly indicating initial access via unauthorized browser extensions or localized session hijacking software. This advisory provides strategic context, detection engineering leads, and posture hardening recommendations to mitigate RMM abuse, browser-based session hijacking, and identity compromise. 

Threat Overview and Strategic Impact

Threat actors are increasingly abandoning custom malware payloads in favor of abusing legitimate enterprise tools. By abusing widely trusted commercial utilities (such as ScreenConnect, AnyDesk, TeamViewer, Atera, or Splashtop), adversaries bypass standard antivirus signatures and blend command and control traffic into normal administrative network flows.

In these campaigns, the adversaries leverage valid user sessions to execute financial diversion fraud and internal phishing without triggering perimeter email controls. By registering new Multi-Factor Authentication devices immediately following access, the threat actors establish persistence while modifying payroll routing details and viewing sensitive employee PII. Simultaneously, internal phishing campaigns can be launched to deploy non-whitelisted remote management software. The impact includes potential payroll diversion loss, exposure of regulatory-protected PII, and unauthorized endpoint control. These campaigns highlight key organizational risks: unmonitored browser extensions, absent application control/whitelisting for administrative tools, and incomplete endpoint scanning regimes.

Security Hardening and Recommendations

Organizations should enforce Application Control and Software Whitelisting (e.g., AppLocker, WDAC) to block the execution and installation of all non-approved RMM and remote access tools. Implement Centralized Browser Extension Management via Group Policy, managed browsers or MDM to restrict extensions strictly to a curated, enterprise-approved list. Enforce phishing-resistant MFA to mitigate token/session hijacking via browser intermediaries. 

Detection Strategy

Detection must focus on identifying unauthorized RMM execution and anomalous identity behavior. Audit endpoint logs for process creations matching RMM binaries or installers (e.g., ConnectWiseControl.Client.exe, Setup.exe with ScreenConnect command-line arguments) originating from untrusted locations or running under non-IT accounts. Monitor identity logs for sudden MFA device additions followed immediately by modifications to high-risk SaaS attributes (such as banking information or mass document GET requests). Track internal email patterns for high-volume distributions containing external URL links or file downloads.

How Deepwatch Protects Our Customers

Deepwatch provides end-to-end defense against machine-speed, AI-orchestrated threat campaigns through a combination of expert-led operations and automated response capabilities:

  • 24/7 Continuous Expert Monitoring: Deepwatch experts continuously monitor customer environments around the clock to detect, investigate, and triage suspicious activity in real time.
  • Threat Intelligence & Analysis: Our Threat Intelligence team actively tracks, collects, and analyzes evolving adversary TTPs and IOCs, to provide early awareness of emerging agentic AI attack trends.
  • Continuous Detection Engineering: Detection Engineers constantly review, update, and deploy high-fidelity alerting to keep pace with the latest threat landscape evolutions.
  • Proactive Threat Hunting: Deepwatch Threat Hunters regularly perform IOC retrohunts across historical customer telemetry to identify latent threat activity or newly disclosed indicators.
  • Dynamic Risk Scoring (DRS): Deepwatch DRS continuously correlates and weighs individual low-severity behavioral signals into an aggregated, high-fidelity risk score to elevate critical threats automatically.

Relevant Detections

  • Please visit the Guardian Platform to access the relevant detections for this activity.

Threat Hunting Leads

  • Search process execution logs for common commercial RMM tools (ScreenConnect, AnyDesk, TeamViewer, Atera, Splashtop, LogMeIn) executed outside standard IT deployment software pipelines or by non-admin user accounts. 
  • Query IdP/MFA audit logs for accounts that added a new MFA device and modified bank details or executed high-volume SaaS data reads within 24 hours. 
  • Inspect endpoint telemetry for web browser processes spawning unverified child installer binaries or writing unverified CRX/browser extension files to disk.

Technical Artifacts 

Please visit the Guardian Platform to access the associated technical artifacts.

Threat Object Mapping

Intrusion Set:

  • Unattributed

Attack Pattern (MITRE ATT&CK/MITRE ATLAS):

TacticTechniqueTechnique IDAssociated Threat Activity

Initial Access

Valid Accounts

T1078

Session hijacking / compromise of valid internal user accounts.


Persistence

Modify Authentication Process: Multi-Factor Authentication


T1556.006

Addition of adversary-controlled MFA registration devices post-compromise.

Credential Access / Collection

Adversary-in-the-Middle / Steal Web Session Cookie

T1539 / T1185

Interruption of login session leading to credential/session capture via browser hijacking.

Stealth

Abuse of Legitimate System Tools

T1218

Execution of non-whitelisted dual-use RMM software to evade traditional endpoint defenses.

Command and Control

Remote Access Software

T1219

Staging and distribution of legitimate RMM software for external command and control.

Vulnerabilities:

  • N/A (Exploitation of valid credentials and social engineering rather than CVEs)

Malware/Tool:

  • RMM Software (ScreenConnect, AnyDesk, TeamViewer, Atera, etc., abused for C2)
  • Malicious / Unauthorized Browser Extensions

Additional Sources

Share

LinkedIn Twitter Facebook