Abuse of Action1 RMM Tools in Phishing Campaigns
Runtime Rebel is tracking a trend where legitimate Remote Monitoring and Management (RMM) tools are being co-opted by threat actors to establish persistence and control over compromised systems. A recent analysis by SANS Internet Storm Center (ISC) highlights the abuse of Action1 RMM software in active phishing campaigns, mirroring earlier observations of ScreenConnect client exploitation. This tactic allows attackers to bypass traditional security controls by leveraging trusted, signed applications and their associated cloud infrastructure.
The use of legitimate software by malicious actors complicates detection and response efforts, as the deployed tools themselves are not inherently malicious. Instead, their unauthorized deployment and subsequent use for nefarious purposes constitute the threat. Security professionals must understand these sophisticated attack chains to effectively protect their organizations.
Technical Overview of the Attack Chain
The attack typically initiates with a phishing email, designed to lure recipients into opening a malicious attachment. In the observed campaigns, these emails masqueraded as fake PDF invoices. When opened, these PDFs did not display an invoice directly; instead, they exploited PDF features like OpenAction and URI keywords to redirect the victim’s browser to a malicious VBS (Visual Basic Script) file. This technique avoids direct URL embedding in emails, enhancing evasion of email security gateways.
The downloaded VBS file, often unobfuscated, serves a dual purpose: it displays a benign, non-blurred decoy PDF (the intended fake invoice) to the user while silently downloading and installing a malicious MSI (Microsoft Installer) archive in the background. The MSI package contains four files identified as belonging to the Action1 RMM tool. These files are legitimately signed with an “Action1 Corporation” certificate, which remains valid until May 2026, further complicating detection by reputation-based security tools.
Persistence and Command-and-Control
Upon execution, the Action1 RMM tool establishes persistence by installing itself as a service named “A1Agent” (Action1 Agent), executing C:\Windows\Action1\action1_agent.exe. Registry keys such as HKLM\Software\Action1\Agent are populated with critical information including CustomerId, Certificate, PrivateKey, MSI, and INSTALLDIR. The observed CustomerId (e.g., 49b18106-681d-456a-b098-092e2818c09a) indicates a specific account used by the threat actor. This agent then connects to the legitimate Action1 infrastructure via server[.]na-2.action1[.]com, allowing the attackers to leverage the vendor’s cloud platform, likely through a free or test account, for remote management.
Another observed sample mimicking a DHL document followed a similar pattern, delivering the same MSI file via a ZIP archive containing an HTA script. This indicates a consistent operational methodology across different themed phishing lures.
Actionable Recommendations for Defenders
Organizations need a multi-layered defense strategy to counter the sophisticated abuse of Action1 RMM tools and similar legitimate software. Focusing solely on blocking known malware signatures is insufficient when attackers use trusted executables.
How to Detect Action1 RMM Abuse
To detect Action1 RMM abuse, security teams should prioritize the following:
- Email Security: Implement advanced email filtering solutions capable of detecting malicious attachments, suspicious URI redirects within PDFs, and unusual file types or download chains. Train users to recognize phishing attempts, especially those mimicking invoices or delivery notifications.
- Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor for suspicious process execution, service creation (
A1Agent), and registry modifications (HKLM\Software\Action1\Agent). Look for legitimate RMM tools being installed outside of approved IT deployment processes. - Network Monitoring: Monitor network traffic for connections to known RMM vendor infrastructure (
server[.]na-2.action1[.]com) from unauthorized or unmanaged endpoints. Anomalous outgoing connections from user workstations to RMM platforms should trigger alerts. - Application Whitelisting: Implement strict application whitelisting policies to prevent unauthorized software from executing. While legitimate RMM tools may be whitelisted for IT, restrict their installation to specific directories and by authorized accounts.
Mitigating RMM Tool Exploitation
To mitigate RMM tool exploitation, consider these proactive measures:
- User Awareness Training: Regular, up-to-date training on identifying phishing emails, especially those delivering fake PDF invoices or other enticing lures.
- Principle of Least Privilege: Ensure users operate with the fewest possible privileges required for their tasks, limiting their ability to install unauthorized software.
- Vulnerability Management: While Action1 itself is not vulnerable in this scenario, ensure all other software is regularly patched to close potential entry points that could lead to initial compromise.
- Review RMM Usage: Regularly audit legitimate RMM tool installations across your environment to ensure they are only present on authorized systems and used by approved personnel. Remove or disable any unauthorized installations promptly.
Related: ScreenConnect Client Abused in Phishing Campaigns, Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends