RMM Abuse, Session Hijacking, Identity Compromise, BEC, Internal Phishing, Browser Extensions
Source Material: CISA | Hacker News | Technology: Remote Monitoring and Management | Targeted Industries: Opportunistic
Executive Summary
The Deepwatch Adversary Tactics & Intelligence team has recently observed an increase in incidents involving credential compromise, session hijacking, and RMM utility abuse across sectors. The threat actors use techniques to gain unauthorized access to internal identities, alter MFA registration devices, modify/view payroll deposit details, and systematically access sensitive HR/PII documents housed within HR and administrative tools.To expand their access and establish persistent footholds, the threat actors utilize compromised internal identities to distribute internal phishing communications. These emails entice internal recipients to download and execute legitimate Remote Monitoring and Management (RMM) applications, using authorized system administration software as covert Command and Control channels. Attackers are also observed utilizing phone, chat, and internal email impersonation to trick help desk teams into resetting passwords, MFA, granting unauthorized access, or installing remote software under the guise of urgent IT support.
Investigations revealed that affected users experienced abnormal login session disruptions prior to account takeover, strongly indicating initial access via unauthorized browser extensions or localized session hijacking software. This advisory provides strategic context, detection engineering leads, and posture hardening recommendations to mitigate RMM abuse, browser-based session hijacking, and identity compromise.
Threat Overview and Strategic Impact
Threat actors are increasingly abandoning custom malware payloads in favor of abusing legitimate enterprise tools. By abusing widely trusted commercial utilities (such as ScreenConnect, AnyDesk, TeamViewer, Atera, or Splashtop), adversaries bypass standard antivirus signatures and blend command and control traffic into normal administrative network flows.
In these campaigns, the adversaries leverage valid user sessions to execute financial diversion fraud and internal phishing without triggering perimeter email controls. By registering new Multi-Factor Authentication devices immediately following access, the threat actors establish persistence while modifying payroll routing details and viewing sensitive employee PII. Simultaneously, internal phishing campaigns can be launched to deploy non-whitelisted remote management software. The impact includes potential payroll diversion loss, exposure of regulatory-protected PII, and unauthorized endpoint control. These campaigns highlight key organizational risks: unmonitored browser extensions, absent application control/whitelisting for administrative tools, and incomplete endpoint scanning regimes.
Security Hardening and Recommendations
Organizations should enforce Application Control and Software Whitelisting (e.g., AppLocker, WDAC) to block the execution and installation of all non-approved RMM and remote access tools. Implement Centralized Browser Extension Management via Group Policy, managed browsers or MDM to restrict extensions strictly to a curated, enterprise-approved list. Enforce phishing-resistant MFA to mitigate token/session hijacking via browser intermediaries.
Detection Strategy
Detection must focus on identifying unauthorized RMM execution and anomalous identity behavior. Audit endpoint logs for process creations matching RMM binaries or installers (e.g., ConnectWiseControl.Client.exe, Setup.exe with ScreenConnect command-line arguments) originating from untrusted locations or running under non-IT accounts. Monitor identity logs for sudden MFA device additions followed immediately by modifications to high-risk SaaS attributes (such as banking information or mass document GET requests). Track internal email patterns for high-volume distributions containing external URL links or file downloads.
How Deepwatch Protects Our Customers
Deepwatch provides end-to-end defense against machine-speed, AI-orchestrated threat campaigns through a combination of expert-led operations and automated response capabilities:
- 24/7 Continuous Expert Monitoring: Deepwatch experts continuously monitor customer environments around the clock to detect, investigate, and triage suspicious activity in real time.
- Threat Intelligence & Analysis: Our Threat Intelligence team actively tracks, collects, and analyzes evolving adversary TTPs and IOCs, to provide early awareness of emerging agentic AI attack trends.
- Continuous Detection Engineering: Detection Engineers constantly review, update, and deploy high-fidelity alerting to keep pace with the latest threat landscape evolutions.
- Proactive Threat Hunting: Deepwatch Threat Hunters regularly perform IOC retrohunts across historical customer telemetry to identify latent threat activity or newly disclosed indicators.
- Dynamic Risk Scoring (DRS): Deepwatch DRS continuously correlates and weighs individual low-severity behavioral signals into an aggregated, high-fidelity risk score to elevate critical threats automatically.
Relevant Detections
- Please visit the Guardian Platform to access the relevant detections for this activity.
Threat Hunting Leads
- Search process execution logs for common commercial RMM tools (ScreenConnect, AnyDesk, TeamViewer, Atera, Splashtop, LogMeIn) executed outside standard IT deployment software pipelines or by non-admin user accounts.
- Query IdP/MFA audit logs for accounts that added a new MFA device and modified bank details or executed high-volume SaaS data reads within 24 hours.
- Inspect endpoint telemetry for web browser processes spawning unverified child installer binaries or writing unverified CRX/browser extension files to disk.
Technical Artifacts
Please visit the Guardian Platform to access the associated technical artifacts.
Threat Object Mapping
Intrusion Set:
- Unattributed
Attack Pattern (MITRE ATT&CK/MITRE ATLAS):
| Tactic | Technique | Technique ID | Associated Threat Activity |
Initial Access | Valid Accounts | T1078 | Session hijacking / compromise of valid internal user accounts. |
Persistence | Modify Authentication Process: Multi-Factor Authentication | T1556.006 | Addition of adversary-controlled MFA registration devices post-compromise. |
Credential Access / Collection | Adversary-in-the-Middle / Steal Web Session Cookie | T1539 / T1185 | Interruption of login session leading to credential/session capture via browser hijacking. |
Stealth | Abuse of Legitimate System Tools | T1218 | Execution of non-whitelisted dual-use RMM software to evade traditional endpoint defenses. |
Command and Control | Remote Access Software | T1219 | Staging and distribution of legitimate RMM software for external command and control. |
Vulnerabilities:
- N/A (Exploitation of valid credentials and social engineering rather than CVEs)
Malware/Tool:
- RMM Software (ScreenConnect, AnyDesk, TeamViewer, Atera, etc., abused for C2)
- Malicious / Unauthorized Browser Extensions
Additional Sources
- https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
- https://www.ic3.gov/CSA/2026/260818.pdf#:~:text=CISA%20%7C%20FBI%20%7C%20HHS.%20Page%202,Bureau%20of%20Investigation%20(FBI)%2C%20Cybersecurity%20and%20Infrastructure.
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Share