Back to Feed
MalwareMar 3, 2026

Signed malware impersonating workplace apps deploys RMM backdoors

Attackers deployed signed malware using stolen EV certificates to impersonate legitimate workplace applications and establish persistent backdoor access via Remote Management and Monitoring (RMM) tools in enterprise environments. The campaign highlights the misuse of code signing certificates to bypass security controls and deploy legitimate tools for malicious purposes. Organizations are advised to strengthen certificate validation controls and implement enhanced monitoring of RMM tool activity.

Summary

Attackers deployed signed malware using stolen EV certificates to impersonate legitimate workplace applications and establish persistent backdoor access via Remote Management and Monitoring (RMM) tools in enterprise environments. The campaign highlights the misuse of code signing certificates to bypass security controls and deploy legitimate tools for malicious purposes. Organizations are advised to strengthen certificate validation controls and implement enhanced monitoring of RMM tool activity.