Who sees who? Experts uncover criminals using fake corporate software to gain access to company systems


  • Proofpoint uncovered fake RMM tool “TrustConnect” built as cover for RAT malware
  • Criminals created site, paid for certificate, tricked companies into $300/month subscriptions
  • The tool gave the attackers full remote control; linked to Redline infostealer customer

A group of cybercriminals went to great lengths to infect companies with a remote access trojan (RAT), set up an entire company, vibe code a website, and pay thousands for a legitimate certificate.

In its report, Proofpoint said it was quite common for cybercriminals to use legitimate remote monitoring and management (RMM) tools in their technology stack. They would trick their victims into installing their favorite tool and share login information, which would enable them to deploy all sorts of stage-two malware, including info stealers, remote access Trojans, or ransomware.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top