Threat report

www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access

https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access
Published on
www.microsoft.com

ATT&CK techniques those detections carry

  • T1219Remote Access Tools
  • T1219.002Remote Desktop Software
  • T1036Masquerading
  • T1105Ingress Tool Transfer
  • T1204User Execution
  • T1204.002Malicious File
Open the original

2 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Lure-Themed Internet-Delivered RMM ExecutableMedium
Potential RMM Execution from a Commonly Abused Web ServiceLow

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice