[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9K9jSNLzB2KeWqRzSo3QATCfANqbooz7LnqN8ExH4FM":3},{"article":4,"iocs":37,"watch_terms":38},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"7e94cf9c-78b6-4b1e-ae71-271ae846987c","Signed malware impersonating workplace apps deploys RMM backdoors","signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors","Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure. The post Signed malware impersonating workplace apps deploys RMM backdoors appeared first on Microsoft Security Blog.","Attackers deployed signed malware using stolen EV certificates to impersonate legitimate workplace applications and establish persistent backdoor access via Remote Management and Monitoring (RMM) tools in enterprise environments. The campaign highlights the misuse of code signing certificates to bypass security controls and deploy legitimate tools for malicious purposes. Organizations are advised to strengthen certificate validation controls and implement enhanced monitoring of RMM tool activity.",null,"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F03\u002Fsigned-malware-impersonating-workplace-apps-deploys-rmm-backdoors\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F03\u002FMS_Actional-Insights_Malware-ransomware-1.jpg","2026-03-03T21:11:03+00:00","2026-03-15T06:36:25.716027+00:00",8,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":17,"icon":10,"name":19,"slug":20},"Malware","malware",[22,27,32],{"category":23},{"id":24,"icon":10,"name":25,"slug":26},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":28},{"id":29,"icon":10,"name":30,"slug":31},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":33},{"id":34,"icon":10,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]