ASEC reported phishing campaigns that distribute malicious PDF files which redirect victims to disguised download pages (e.g., fake Google Drive or adobe-download-pdf[.]com) to install legitimate RMM tools (Syncro, ScreenConnect, NinjaOne, SuperOps) signed with the same certificate. The activity shows repeated use of signed RMM installers and downloaders since at least October 2025, indicating a persistent actor leveraging legitimate remote-management software for unauthorized access. #Syncro #ScreenConnect
Keypoints
- Threat actors distributed PDFs with names like “Invoice” or “Defective_Product_Oder.pdf” that display a high-quality image or error message to force users to click a link to a fake Google Drive or adobe-download-pdf[.]com page.
- Phishing pages lead to files disguised as video downloads (e.g., “Video_recorded_on_iPhone17.mp4”) which are actually installers that deploy RMM tools or downloaders when executed.
- Multiple RMM solutions were abused: Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were observed among samples signed with the same certificate.
- Samples included full RMM installers (created with Advanced Installer) and NSIS-based downloaders whose scripts fetch additional payloads and reference “NinjaOne”.
- At least one certificate used to sign malicious installers ties these campaigns together and indicates activity dating back to October 2025 and intensive distribution in the second half of 2025.
- Syncro installers observed contained execution parameters like “key” and “customerid” (e.g., key: yK0UAOaHHwdbYDOp_sr51w; customerid: 1709830), suggesting reuse by the same actor.
- RMM misuse has precedent: Syncro and ScreenConnect have previously been leveraged by ransomware and APT groups (e.g., Chaos, Royal, MuddyWater, ALPHV/BlackCat, Hive), highlighting the risk of legitimate remote-management tools in attacks.
MITRE Techniques
- No MITRE ATT&CK techniques were explicitly named in the article.
Indicators of Compromise
- [File Hash – MD5] Malware samples and installers – 0578e58a356ff3872028024d0e5455b8, 09bc8258b13cde77eda9df8557679023, and 3 more hashes
- [URL] Phishing and fake download pages – https[:]//adobe-download-pdf[.]com/43taHls, https[:]//adobe-download-pdf[.]com/4o8R8Gx, and other malicious links such as https[:]//anhemvn124[.]com/
- [URL (disguised drive pages) ] Google Drive spoof pages used to host/download payloads – https[:]//dirvegoogle[.]com/Video_defective_product[.]mp4/view, https[:]//dirvegoogle[.]com/Video_recorded_on_iPhone17[.]mp4/view
- [FQDN ] Domain used in Drive impersonation – dirvegoogle[.]com
- [File names ] Distributed lure and downloaded files – Defective_Product_Oder.pdf, Invoice_Details.PDF, and downloaded filename “Video_recorded_on_iPhone17.mp4 Drive.google.com”
Read more: https://asec.ahnlab.com/en/91995/