Findings
-
[1] 2026-09-29 Phishing Abuses RMM Tools for Persistent Access
In this article Attack chain overviewMitigation and protection guidanceLearn More In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures,… The installer subsequently dropped multiple installation components, including System.dll, nsExec.dll, and UAC.dll, to the following folder paths before relaunching itself through an elevation workflow generated by the installer framework. Next, the installer invoked a Windows User Account Control (UAC) elevation… The execution of these files occurred through ScreenConnect’s built-in RunFile functionality, which allows files to be transferred to and executed on managed endpoints. This activity demonstrates how the threat actor leveraged a legitimate MSP360 RMM deployment to establish an initial… DeviceProcessEvents | where Timestamp >= ago(30d) | where (InitiatingProcessVersionInfoCompanyName == "MSP360" and ProcessCommandLine == ""powershell.exe"") or ( InitiatingProcessCommandLine == ""powershell.exe"" and ProcessCommandLine has_all ("msiexec.exe","\Temp\",".msi") and InitiatingProcessParentFileName == "RMM.Agent.exe") // Run this query to identify the suspicious network connections from the… IndicatorTypeDescription•108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dcSHA256Legitimate MSP360 RMM v2.5.0.67 installer observed being distributed under deceptive filenames during the campaign. The observed sample was signed using a certificate that has since been revoked.•f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97•857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3•6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e•4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26SHA256Legitimate MSP360 RMM Agent Service observed during the campaign•adswre[.]cfd•trews[.]cfd•swedcorry[.]stefneyv[.]com•ojsuyw[.]niyari[.]org•bunstar[.]harej[.]si•adsaw[.]cfd•sdfghj[.]rd-team[.]ruDomainsDomains contacted by ScreenConnect clients in…
-
[2] 2026-09-29 Beyond source code: A path to the keys to the kingdom
What began as a single compromised identity quickly expanded into an organization’s development and cloud environments. In our latest Cyberattack Series report, we examine how the Microsoft Detection and Response Team (DART)—the team that delivers Microsoft Defender Experts Cybersecurity Incident… INSIGHT: Identities are the new attack pathThis incident demonstrates how a single compromised identity can provide access to development platforms, cloud resources, and production environments when those systems are tightly connected. As this case demonstrates, a single compromised identity can become…
-
[3] 2026-09-29 Star Blizzard refines phishing and malware delivery with the RedFlick technique
In this article Star Blizzard TTPs observed in 2026Defending against Star Blizzard and RedFlick-related activityMicrosoft Defender detectionsHunting queriesIndicators of compromise Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing… “Invitation to a Closed CES Roundtable Discussion” – Initial contact campaign targeting US and Europe technology-sector organizations. Respondents received a RedFlick lure attachment. “Atlantic Council Closed-Door Strategic Discussion” – Initial contact campaign targeting government officials, foreign policy practitioners, security researchers,… In mid-January 2026, Microsoft observed the use of a malicious Virtual Hard Disk v2 (VHDX), delivered through a phishing email containing a password-protected ZIP file. The VHDX file ships a malicious LNK file disguised as a PDF document, alongside a… Star Blizzard’s shift from ClickFix-based delivery chains to VHDX files, expanded use of scheduled tasks for persistence, and concealment of payloads within PDF files demonstrate the actor’s continued ability to adapt their delivery methods in response to evolving defenses. The… Configure Microsoft Defender for Office 365 to recheck links on click. Safe Links provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages, other Office 365 applications such… Invoke SSH to launch local command line The following query will detect the invocation of SSH to initiate a local command prompt, which Star Blizzard used in January 2026 to download and execute a remotely hosted MSI installer. (Note that…
-
[4] 2026-09-29 OperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities. The post OperTraitors: How Kubernetes Operators Betray Your Security Posture appeared first on Unit 42.
Where Kimbodo Comes In
Kimbodo builds and operates this in production for businesses — see our AI Security & Guardrails practice, or Request a Security Review.