132. Threat Actors Abuse N‑sight RMM to Attack Brazilian Organizations

Hello everyone!

Adversaries keep showing interest in legitimate tools, especially RMMs. Accoring to Cisco Talos report, the threat actors executed a spam campaign against Brazilian users, weaponizing N‑sight RMM.

It's interesting enough, that N-able also provides security solutions and MDR service. It makes such tools even more trusted. For example, the RMM agent currently has 0 detections on VirusTotal.

For example, we can use product-related metadata to build our hunting query:

event_type: "processcreatewin"

AND

proc_file_productname: "Advanced Monitoring Agent"

Also, you may want to hunt for file creation event in related folders:

event_type: "filecreatewin"

AND

file_path: "Advanced Monitoring Agent"

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

068. Detecting RMMs from Ransomware Affiliate's Toolkit: MeshAgent