Threat Actors Abuse Action1 RMM Tool via Phishing
Threat actors are actively exploiting Action1 RMM tools, leveraging phishing emails with fake PDF invoices to deliver malicious VBS and MSI files.
- Threat actors are actively abusing Action1 RMM tools, installing them via phishing to gain remote access to victim systems.
- Systems are affected by the installation of the legitimate Action1 Agent, disguised through malicious VBS and MSI files.
- Implement robust email security, user training, and network monitoring to detect and block suspicious RMM installations.