RMM Tools (Syncro, SuperOps, NinjaOne, etc.) Being Distributed Disguised as Video Files

RMM Tools (Syncro, SuperOps, NinjaOne, etc.) Being Distributed Disguised as Video Files

ASEC reported phishing campaigns that distribute malicious PDF files which redirect victims to disguised download pages (e.g., fake Google Drive or adobe-download-pdf[.]com) to install legitimate RMM tools (Syncro, ScreenConnect, NinjaOne, SuperOps) signed with the same certificate. The activity shows repeated use of signed RMM installers and downloaders since at least October 2025, indicating a persistent actor leveraging legitimate remote-management software for unauthorized access. #Syncro #ScreenConnect

Keypoints

  • Threat actors distributed PDFs with names like “Invoice” or “Defective_Product_Oder.pdf” that display a high-quality image or error message to force users to click a link to a fake Google Drive or adobe-download-pdf[.]com page.
  • Phishing pages lead to files disguised as video downloads (e.g., “Video_recorded_on_iPhone17.mp4”) which are actually installers that deploy RMM tools or downloaders when executed.
  • Multiple RMM solutions were abused: Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were observed among samples signed with the same certificate.
  • Samples included full RMM installers (created with Advanced Installer) and NSIS-based downloaders whose scripts fetch additional payloads and reference “NinjaOne”.
  • At least one certificate used to sign malicious installers ties these campaigns together and indicates activity dating back to October 2025 and intensive distribution in the second half of 2025.
  • Syncro installers observed contained execution parameters like “key” and “customerid” (e.g., key: yK0UAOaHHwdbYDOp_sr51w; customerid: 1709830), suggesting reuse by the same actor.
  • RMM misuse has precedent: Syncro and ScreenConnect have previously been leveraged by ransomware and APT groups (e.g., Chaos, Royal, MuddyWater, ALPHV/BlackCat, Hive), highlighting the risk of legitimate remote-management tools in attacks.

MITRE Techniques

  • No MITRE ATT&CK techniques were explicitly named in the article.

Indicators of Compromise

  • [File Hash – MD5] Malware samples and installers – 0578e58a356ff3872028024d0e5455b8, 09bc8258b13cde77eda9df8557679023, and 3 more hashes
  • [URL] Phishing and fake download pages – https[:]//adobe-download-pdf[.]com/43taHls, https[:]//adobe-download-pdf[.]com/4o8R8Gx, and other malicious links such as https[:]//anhemvn124[.]com/
  • [URL (disguised drive pages) ] Google Drive spoof pages used to host/download payloads – https[:]//dirvegoogle[.]com/Video_defective_product[.]mp4/view, https[:]//dirvegoogle[.]com/Video_recorded_on_iPhone17[.]mp4/view
  • [FQDN ] Domain used in Drive impersonation – dirvegoogle[.]com
  • [File names ] Distributed lure and downloaded files – Defective_Product_Oder.pdf, Invoice_Details.PDF, and downloaded filename “Video_recorded_on_iPhone17.mp4   Drive.google.com”


Read more: https://asec.ahnlab.com/en/91995/