Hackers Leverage LogMeIn Resolve and ScreenConnect In Phishing Attacks

Cybersecurity researchers have uncovered a sophisticated phishing campaign that exploits legitimate remote monitoring and management (RMM) software to infiltrate corporate networks.

According to a recent threat report, attackers are actively tricking users into installing LogMeIn Resolve and ScreenConnect to establish persistent, unauthorized access to compromised systems.

This activity, tracked as STAC6405, affected over 80 organizations across multiple sectors, primarily in the United States, with the bulk of the malicious activity occurring between October and November 2025.

The attack chain typically begins with deceptive emails sent from compromised third-party accounts, making the messages appear to come from known and trusted senders.

Many of these phishing lures are designed to look like event invitations, often mimicking the popular platform Punchbowl with subject lines such as “SPECIAL INVITATION.” Other variations include fake invitations to bid on corporate tenders.

Second-Stage Payloads and Data Theft

In the majority of observed incidents, the attack concluded once the initial RMM tool was successfully installed.

Cybersecurity experts suggest these attackers might be acting as initial access brokers, holding the compromised systems to sell on dark web marketplaces, or simply waiting to see if their presence is detected.

An example of one of the malicious lures (Source: sophos)
An example of one of the malicious lures (Source: sophos)

However, in specific cases, the threat actors rapidly advanced to a more destructive second stage. Using either the newly installed LogMeIn Resolve or pre-existing ScreenConnect instances, the attackers downloaded additional malicious payloads onto the compromised devices.

One notable payload was a ZIP file packed with HeartCrypt, a known malware evasion tool. This file contained a sophisticated information-stealing module that was injected into a legitimate video game binary to evade detection.

A Norton-themed distribution website (Source: sophos)
A Norton-themed distribution website (Source: sophos)

To bypass automated security sandboxes, the malware was programmed to remain completely idle for up to 9 minutes before executing, using a series of complex nested loops to delay its activity.

Following execution of the downloaded binary, LogMeIn Resolve is installed (Source: sophos)
Following execution of the downloaded binary, LogMeIn Resolve is installed (Source: sophos)

Once active, it injected malicious code into legitimate Microsoft processes. It established a connection with an external command-and-control server.

ToolLegitimate PurposeAttack Abuse
LogMeIn ResolveRemote monitoring and management (RMM) for IT supportDistributed via fake event invitations; silently installed to grant unattended, persistent backdoor access to compromised devices .
ScreenConnectRemote desktop software for administration and troubleshootingUsed as a second-stage payload delivery mechanism to drop HeartCrypt-packed infostealers or interactive Remote Access Trojans (RATs) .

According to Sophos research, this campaign highlights a growing and dangerous trend in the cybersecurity landscape.

Rather than immediately deploying custom malware that modern endpoint protection platforms might quickly catch, hackers are increasingly relying on abusing trusted third-party infrastructure.

By leveraging legitimate IT administration tools to establish an initial foothold, cybercriminals can maintain stealthy, long-term access to corporate networks, leaving organizations vulnerable to devastating data breaches and ransomware attacks.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories