TL;DR

Criminals are offering a RAT disguised as legitimate RMM software for $300 per month, posing as a trusted vendor in the market.

What happened

Proofpoint researchers uncovered a scheme where criminals sell a Remote Access Trojan (RAT) disguised as legitimate remote monitoring and management (RMM) software. The fake vendor appears to be trustworthy and offers monthly subscription services for $300.

Why it matters for ops

This trend highlights the need for enhanced vigilance in vetting RMM vendors and conducting thorough security assessments of tools used within operational environments.

Action items

  • Implement strict policies for RMM software procurement
  • Conduct regular audits to detect potential RAT compromises
  • Educate staff on recognizing signs of fraudulent RMM providers

Source link

https://go.theregister.com/feed/www.theregister.com/2026/02/19/rmm_rat_trustconnect/