Threats · 5h ago
SANS ISC found a phishing campaign that uses a fake PDF invoice to start a chain that ends in Action1 Remote Access being installed on the victim host. Opening the PDF triggers an OpenAction/URI link that pulls down a VBS file, and that script fetches an MSI package containing Action1 RMM components.
The important part is not just the malware drop. The installed agent enrolls the machine into Action1’s cloud infrastructure, so the attacker can manage it through vendor-hosted traffic that looks like ordinary remote-admin activity. That makes IP blocking and routine command-and-control hunting far less useful when the control channel rides on legitimate Action1 domains and certificates.
For defenders who allow remote-management SaaS, the exposure sits in the trust placed in that traffic: once a hostile host joins a real RMM tenant, the malicious control can blend into a channel many environments already permit. The reporting also suggests the abuse may be tied to disposable or test access, but it does not settle how widely the campaign is spread.
1 source covering this story
More RMM Tools In the Wild - SANS Internet Storm Center
More RMM Tools In the Wild, Author: Xavier Mertens
Part of the PlainSec briefing for 2026-10-06