In December 2024, GoSecure Threat Hunters have identified a concerning use of remote access software by cybercriminals to gain initial access within corporate environments. The attackers start by flooding a victim’s email with spam and then pose as IT support via Microsoft Teams. This social engineering tactic lures victims into installing remote access software, which is then exploited to deploy a custom implant that exfiltrates sensitive information and sets the stage for ransomware attacks. 

Why This Matters 

The use of remote access software as an attack vector is particularly alarming because it exploits the human element: employees’ trust in their IT departments. This method bypasses typical security measures and allows attackers to gain deep access without immediate detection. The threat actors’ ability to remain undetected on the network long enough to deploy ransomware poses a significant risk to organizational security. 

Detection and Monitoring 

Our Threat Hunters hypothesized that cybercriminals are leveraging social engineering to exploit remote access software for network infiltration. Through diligent validation and threat hunting, our team confirmed no adversaries were present within our managed clients’ environments. However, we have established robust detection rules to continuously monitor for suspicious activities related to remote access tools: 

Detection Rule: Execution of Discovery Techniques followed by RMM Tool Usage
Description: Detects when system information and network configuration commands are followed by the execution of a remote access tool, indicating potential unauthorized activity. 

Recommendations 

Organizations are advised to standardize the use of remote access software within their environments and block unapproved tools at the network level. We also recommend enhancing endpoint detection capabilities and educating users about the risks associated with unsolicited IT support communications. 

Conclusion 

The December Threat Hunt highlights the evolving nature of cyber threats and emphasizes the importance of vigilance and advanced detection strategies. GoSecure’s MXDR service is specifically designed to provide comprehensive surveillance and proactive threat mitigation to protect against sophisticated cyber threats, including those utilizing remote access software. For further details on bolstering your defenses, or to discuss our findings and recommendations, please contact us directly at (888)-287-5858 or info@gosecure.ai. 

Stay secure! 

Your GoSecure Threat Hunting Team 

GoSecure Titan® Managed Extended Detection & Response (MXDR)​

GoSecure Titan® Managed Extended Detection & Response (MXDR)​ Foundation

GoSecure Titan® Vulnerability Management as a Service (VMaaS)

GoSecure Titan® Managed Security Information & Event Monitoring (Managed SIEM)

GoSecure Titan® Managed Perimeter Defense​ (MPD)

GoSecure Titan® Inbox Detection and Response (IDR)

GoSecure Titan® Secure Email Gateway (SEG)

GoSecure Titan® Threat Modeler

GoSecure Titan® Identity

GoSecure Titan® Platform

GoSecure Professional Security Services

Incident Response Services

Security Maturity Assessment

Privacy Services

PCI DSS Services

Penetration Testing Services​

Security Operations

MicrosoftLogo

GoSecure MXDR for Microsoft

Comprehensive visibility and response within your Microsoft security environment

USE CASES

Cyber Risks

Risk-Based Security Measures

Sensitive Data Security

Safeguard sensitive information

Private Equity Firms

Make informed decisions

Cybersecurity Compliance

Fulfill regulatory obligations

Cyber Insurance

A valuable risk management strategy

Ransomware

Combat ransomware with innovative security

Zero-Day Attacks

Halt zero-day exploits with advanced protection

Consolidate, Evolve & Thrive

Get ahead and win the race with the GoSecure Titan® Platform

24/7 MXDR FOUNDATION

GoSecure Titan® Endpoint Detection and Response (EDR)

GoSecure Titan® Next Generation Antivirus (NGAV)

GoSecure Titan® Security Information & Event Monitoring (SIEM)

GoSecure Titan® Inbox Detection and Reponse (IDR)

GoSecure Titan® Intelligence

OUR SOC

Proactive Defense, 24/7

ABOUT GOSECURE

GoSecure is a recognized cybersecurity leader and innovator, pioneering the integration of endpoint, network, and email threat detection into a single Managed Extended Detection and Response (MXDR) service. For over 20 years, GoSecure has been helping customers better understand their security gaps and improve their organizational risk and security maturity through MXDR and Professional Services solutions delivered by one of the most trusted and skilled teams in the industry.

EVENT CALENDAR

No upcoming events.

LATEST PRESS RELEASE

GOSECURE BLOG

SECURITY ADVISORIES

 24/7 Emergency – (888)-287-5858