A wolf in admin clothing. [Research Saturday]
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “A wolf in admin clothing. [Research Saturday]” inside PodZeus.
This episode of CyberWire Daily's Research Saturday dives into a sophisticated cyber deception campaign dubbed 'Don't Trust Connect: It's a RAT in an RMM Hat.' Threat researcher Selena Larson from Proofpoint details how attackers used AI-generated websites and a legitimate Extended Validation (EV) SSL certificate to masquerade as a legitimate Remote Monitoring and Management (RMM) tool called Trust Connect. The malware, disguised as a trusted RMM, was delivered via phishing emails using common lures like fake party invitations and Social Security Administration notices. Once installed, it functioned as a remote access Trojan (RAT), enabling data theft, lateral movement, and additional malware deployment. Despite the polished front-end, the underlying web development was poorly secured, exposing vulnerabilities that allowed researchers to uncover the scam. The campaign appears linked to the Redline Stealer ecosystem, with the operator using the Telegram handle Zaki09—previously identified as a VIP customer in a major law enforcement takedown. The attackers quickly pivoted after their certificate was revoked, demonstrating a resilient, service-oriented malware operation. The episode underscores that while AI enhances the authenticity of phishing materials, it doesn't replace foundational technical skill—making poor security practices a critical weakness.
AI is being used to create more convincing phishing websites and emails, but poor underlying technical implementation can still expose attackers.
RMM tools are increasingly being abused by threat actors as a trusted delivery mechanism for malware due to their legitimacy and user familiarity.
Organizations should implement strict allowlists and blocklists for RMM tools and monitor for unusual PowerShell or executable behavior.
The use of EV certificates does not guarantee legitimacy—attackers can acquire them to boost credibility, so additional verification is essential.
Threat actors in the malware-as-a-service ecosystem are highly adaptive, quickly pivoting after disruptions, indicating a mature, business-like operation.
…and 1 more takeaway available in PodZeus
The Rise of the Fake RMM: A Wolf in Admin Clothing
“It's a rat in an RMM hat.”
The Deception: How the Fake RMM Lured Victims
Detailed breakdown of the social engineering tactics, including AI-generated websites, fake customer testimonials, and the use of a legitimate Extended Validation certificate to appear trustworthy.
The Infection Chain: From Phishing to RAT Deployment
Explains the typical attack path: phishing emails with fake documents, delivery of the Trust Connect executable, and the malware’s ability to steal data, conduct account takeovers, and move laterally.
Linking to the Redline Stealer Ecosystem
“We think based off of our investigation that they are likely related.”
The AI Paradox: Smoother Front-End, Weaker Back-End
“If you don't have a base knowledge or understanding of something that you're trying to do, it can actually be a vulnerability.”
“If you don't have a base knowledge or understanding of something that you're trying to do, it can actually be a vulnerability.”
“It's a rat in an RMM hat.”
“AI is just a word processor for tooling. It's just another tool in our toolbox.”
Host
Guest
Trust Connect
other
Selena Larson
person
Dave Bittner
person
Redline Stealer
other
Proofpoint
organization
Zaki09
person
Operation Magnus
other
Telegram
other
PowerShell
product
ET Open
other
Water sector feels the pressure.
CyberWire Daily • 26m • 3/31/2026
A war of missiles and messages.
CyberWire Daily • 30m • 4/1/2026
The WhatsApp impostor.
CyberWire Daily • 30m • 4/2/2026
War comes for the cloud.
CyberWire Daily • 30m • 4/3/2026
Startup surge sparks spy interest. [Research Saturday]
CyberWire Daily • 19m • 4/4/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “A wolf in admin clothing. [Research Saturday]” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
