A wolf in admin clothing. [Research Saturday]

CyberWire Daily24mApril 11, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “A wolf in admin clothing. [Research Saturday]” inside PodZeus.

AI-Generated Summary

This episode of CyberWire Daily's Research Saturday dives into a sophisticated cyber deception campaign dubbed 'Don't Trust Connect: It's a RAT in an RMM Hat.' Threat researcher Selena Larson from Proofpoint details how attackers used AI-generated websites and a legitimate Extended Validation (EV) SSL certificate to masquerade as a legitimate Remote Monitoring and Management (RMM) tool called Trust Connect. The malware, disguised as a trusted RMM, was delivered via phishing emails using common lures like fake party invitations and Social Security Administration notices. Once installed, it functioned as a remote access Trojan (RAT), enabling data theft, lateral movement, and additional malware deployment. Despite the polished front-end, the underlying web development was poorly secured, exposing vulnerabilities that allowed researchers to uncover the scam. The campaign appears linked to the Redline Stealer ecosystem, with the operator using the Telegram handle Zaki09—previously identified as a VIP customer in a major law enforcement takedown. The attackers quickly pivoted after their certificate was revoked, demonstrating a resilient, service-oriented malware operation. The episode underscores that while AI enhances the authenticity of phishing materials, it doesn't replace foundational technical skill—making poor security practices a critical weakness.

Key Takeaways
1

AI is being used to create more convincing phishing websites and emails, but poor underlying technical implementation can still expose attackers.

2

RMM tools are increasingly being abused by threat actors as a trusted delivery mechanism for malware due to their legitimacy and user familiarity.

3

Organizations should implement strict allowlists and blocklists for RMM tools and monitor for unusual PowerShell or executable behavior.

4

The use of EV certificates does not guarantee legitimacy—attackers can acquire them to boost credibility, so additional verification is essential.

5

Threat actors in the malware-as-a-service ecosystem are highly adaptive, quickly pivoting after disruptions, indicating a mature, business-like operation.

…and 1 more takeaway available in PodZeus

Chapters
0:00
4 min

The Rise of the Fake RMM: A Wolf in Admin Clothing

It's a rat in an RMM hat.

Highlight
4:00
5 min

The Deception: How the Fake RMM Lured Victims

Detailed breakdown of the social engineering tactics, including AI-generated websites, fake customer testimonials, and the use of a legitimate Extended Validation certificate to appear trustworthy.

9:00
6 min

The Infection Chain: From Phishing to RAT Deployment

Explains the typical attack path: phishing emails with fake documents, delivery of the Trust Connect executable, and the malware’s ability to steal data, conduct account takeovers, and move laterally.

15:00
7 min

Linking to the Redline Stealer Ecosystem

We think based off of our investigation that they are likely related.

Highlight
22:00
8 min

The AI Paradox: Smoother Front-End, Weaker Back-End

If you don't have a base knowledge or understanding of something that you're trying to do, it can actually be a vulnerability.

Highlight
High-Impact Quotes
If you don't have a base knowledge or understanding of something that you're trying to do, it can actually be a vulnerability.
Selena Larson22:36
Viral: 90.0
It's a rat in an RMM hat.
Selena Larson2:03
Viral: 85.0
AI is just a word processor for tooling. It's just another tool in our toolbox.
Selena Larson37:10
Viral: 80.0
Speakers

Host

Dave Bittner

Guest

Selena Larson
Topics Discussed
rmm abuse95%malware-as-a-service90%phishing and social engineering85%ai in cybercrime80%defensive security strategies75%threat intelligence75%zero-trust security70%certificate spoofing65%
People & Brands

Trust Connect

other

18xNegative

Selena Larson

person

12xNeutral

Dave Bittner

person

10xNeutral

Redline Stealer

other

7xNegative

Proofpoint

organization

6xNeutral

Zaki09

person

5xNegative

Operation Magnus

other

5xPositive

Telegram

other

4xNeutral

PowerShell

product

4xNeutral

ET Open

other

3xPositive

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “A wolf in admin clothing. [Research Saturday]” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime