132. Threat Actors Abuse N‑sight RMM to Attack Brazilian Organizations

Hello everyone!

Adversaries keep showing interest in legitimate tools, especially RMMs. Accoring to Cisco Talos report, the threat actors executed a spam campaign against Brazilian users, weaponizing N‑sight RMM.

It's interesting enough, that N-able also provides security solutions and MDR service. It makes such tools even more trusted. For example, the RMM agent currently has 0 detections on VirusTotal.

For example, we can use product-related metadata to build our hunting query:

event_type: "processcreatewin"

AND

proc_file_productname: "Advanced Monitoring Agent"

Also, you may want to hunt for file creation event in related folders:

event_type: "filecreatewin"

AND

file_path: "Advanced Monitoring Agent"

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge