ISC Stormcast For Tuesday, October 6th, 2026 https://isc.sans.edu/podcastdetail/10124

    More RMM Tools In the Wild

    Published: 2026-10-06. Last Updated: 2026-10-06 09:34:56 UTC
    by Xavier Mertens (Version: 1)
    0 comment(s)

    It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.

    Same scenario, it started with a phishing email that delivers a fake PDF invoice to the victim:

    When the PDF is opened, it just redirect to a malicious VBS file. Indeed, the PDF contains an “OpenAction” and “URI” keywords, that sounds weird! 

    remnux@remnux:~/files/samples$ pdf-parser.py Transaction\ Receipt\ .pdf -o 3
    obj 3 0
    Type: /Page
    Referencing: 1 0 R, 2 0 R, 4 0 R
    
      <<
        /Type /Page
        /Parent 1 0 R
        /Resources 2 0 R
        /MediaBox [0 0 595.2799999999999727 841.8899999999999864]
        /Annots
          <<
            /Type /Annot
            /Subtype /Link
            /Rect [0. 841.8899999999999864 595.2799999999999727 71.3010032362460606]
            /Border [0 0 0]
            /A
              <<
                /S /URI
                /URI (hxxps://up-theta-rose.vercel[.]app/adobe_new_update.vbs)
              >>
          >>
        ] /Contents 4 0 R
      >>

    The URL will be visited thanks to the OpenAction. This is a common trick to avoid writing URLs in email bodies that can be easily detected.

    The VBS file is pretty simple and even not obfuscated. It will display another PDF as a decoy: a non-blurred version of the initial attachment.

    In parallel, a MSI archive will be downloaded and installed:

    hxxps://up-theta-rose.vercel[.]app/action1.msi

    The MSI file contains 4 files that are not reported as malicious by VT:

    $ sha256sum *
    eaff35d250c9b04f51c971e70082740dbfeee5dd846829d541f588ad43378727  a1_7z_dll_file
    996b01e15f85e165899630721a141b178a9c372b6e878012180ec9e9d4e7bd06  a1_sas_dll_file
    1b19115d5ebdc216e0ab3adf2c643648cfc70a385f4caf0217c679f9f3b20342  action1_remote_exe
    941695d20d82dd5d62f74b0111feb23720637202f6c797df2a02e2cb6cb6e8e3  main_service_exe

    These files belongs to the RMM tool developed by Action1[2] and are signed with an "Action1 Corporation" certificate that expired in May 2026. 

    The tool installs itself as a service for persistence ("A1Agent" - "Action1 Agent"), executing C:\Windows\Action1\action1_agent.exe.

    The registy key "HKLM\Software\Action1\Agent" contains the values: CustomerId, Certificate, PrivateKey, MSI & INSTALLDIR.

    The CustomerID is: 49b18106-681d-456a-b098-092e2818c09a and is connecting to the Action1 infrastructure via server[.]na-2.action1[.]com.

    We are facing here the same behaviour: the threat actor abuse the cloud infrastructure of the company developing the RMM tool, probably using a free/test account.

    [1] https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388
    [2] https://www.action1.com/remote-access/

    Xavier Mertens (@xme)
    Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
    Xameco | PGP Key

    0 comment(s)

      Comments


      Diary Archives