Cybersecurity researchers have uncovered a sophisticated phishing campaign that exploits legitimate remote monitoring and management (RMM) software to infiltrate corporate networks.
According to a recent threat report, attackers are actively tricking users into installing LogMeIn Resolve and ScreenConnect to establish persistent, unauthorized access to compromised systems.
This activity, tracked as STAC6405, affected over 80 organizations across multiple sectors, primarily in the United States, with the bulk of the malicious activity occurring between October and November 2025.
The attack chain typically begins with deceptive emails sent from compromised third-party accounts, making the messages appear to come from known and trusted senders.
Many of these phishing lures are designed to look like event invitations, often mimicking the popular platform Punchbowl with subject lines such as “SPECIAL INVITATION.” Other variations include fake invitations to bid on corporate tenders.
Second-Stage Payloads and Data Theft
In the majority of observed incidents, the attack concluded once the initial RMM tool was successfully installed.
Cybersecurity experts suggest these attackers might be acting as initial access brokers, holding the compromised systems to sell on dark web marketplaces, or simply waiting to see if their presence is detected.

However, in specific cases, the threat actors rapidly advanced to a more destructive second stage. Using either the newly installed LogMeIn Resolve or pre-existing ScreenConnect instances, the attackers downloaded additional malicious payloads onto the compromised devices.
One notable payload was a ZIP file packed with HeartCrypt, a known malware evasion tool. This file contained a sophisticated information-stealing module that was injected into a legitimate video game binary to evade detection.

To bypass automated security sandboxes, the malware was programmed to remain completely idle for up to 9 minutes before executing, using a series of complex nested loops to delay its activity.

Once active, it injected malicious code into legitimate Microsoft processes. It established a connection with an external command-and-control server.
According to Sophos research, this campaign highlights a growing and dangerous trend in the cybersecurity landscape.
Rather than immediately deploying custom malware that modern endpoint protection platforms might quickly catch, hackers are increasingly relying on abusing trusted third-party infrastructure.
By leveraging legitimate IT administration tools to establish an initial foothold, cybercriminals can maintain stealthy, long-term access to corporate networks, leaving organizations vulnerable to devastating data breaches and ransomware attacks.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.