Email-Delivered RMM: Abusing PDFs for Silent Initial Access

Aug. 7, 2025, 10:21 p.m.

Description

A targeted campaign has been observed since November 2024, primarily affecting organizations in France and Luxembourg. The attackers use socially engineered emails to deliver PDF documents containing embedded links to Remote Monitoring and Management (RMM) tool installers. This method bypasses many email and malware defenses. The PDFs are tailored to the victim's industry and often disguised as invoices, contracts, or property listings. The activity focuses on high-value sectors such as energy, government, banking, and construction. Various RMM tools are used, including FleetDeck, Atera, and Bluetrait. The attackers leverage direct download links and tools that require minimal setup, streamlining the infection process. This approach allows threat actors to gain initial access, disable security features, and potentially deploy subsequent malware using trusted tools.

Date

  • Created: Aug. 7, 2025, 3:19 p.m.
  • Published: Aug. 7, 2025, 3:19 p.m.
  • Modified: Aug. 7, 2025, 10:21 p.m.

Indicators

  • f0119123b86550df9ec2d7946030aab7d387aef37d006eb352498b374c0df941
  • eea65f23c944c5104ec7ee55e4939b51babeddcdbb52459fc2b065434e07e30d
  • e9ba9b7e78607ca072e7cab9890c1742a7f2d82b8a6a6da2c56ac9732dfc9bd9
  • e694758dc5495d71092ea50a8226400d38a18095e6936e063038c65374949016
  • e0ef73289dd4981c3f6a0d8640ea74c6cdb7340129749b44f9dc935bc56fdc33
  • e09524690e24198c1cd5808954ec0e35e09febc9527ae1036be91db605f05faf
  • dc129f059e6d58e1f38e0eed886a5fb165c069a8028a4c7debea1d8a028e0231
  • d3211a41eb9bc727b6de76fe9262ffdf4f38f6c8ca8a6e10d3b82a6be5c07564
  • d19f13124449b4d89028e80579174a3d00cd10e0e28c3dd287b36ff50a5f3d0a
  • c8f077a306b2a960713c374ceb82210eb78975f62c0c5aa1dbb22e36faf949db
  • ae4375eec439b0ee87f01fab2af55dcc5b663d7bc4ed6cd7da3c5c659e7a66fe
  • c025cd3ebd280c88d5e54ce98ff92f6085c064f971e0b01310513939113e95d0
  • c6a8637397a3570c0f153be98303e6b7492c3dac3b94976f6fb2408f46a1763d
  • a8dc8dd2f71366010a74a0e31e21d86a29a418cfc8f7574ce290bb4009417da0
  • a086433cd40c2c44fb76d29698333ffddac950e9dc9c7735cd9bf45194de496c
  • 9dd3d568196bc8f1e417f743422fc017f48554e4604dd670b3ff06d6bf80b957
  • 951ceed3102757d284e84804c4aa002a22502ab72fef10d2317be5192ae8a0ee
  • 9ca4fcd50376d5cdfe86c9274305720b68b9ebadf59acb97f402810f3fcd2fc3
  • 9395edd13d1d71f64b49503fb1c04836bcbb16b9bfe2b3744d4d53f49aa08385
  • 81e3329a89f839952ff0ffbc9cd3e3c80796115184e9b5a0bccba99d806d8b61
  • 8905f6c6f08c4530bc97ec51def19272d9df344b46ad2186265fb77d0db2003c
  • 7e10d37f2abb2bbdf1c4f7bf29277cf01a385301682068a82006563445f80a20
  • 4e392ea104f83c5d154c12f59200755cb8e3cdfaf058000ad24a1896cbb66fa4
  • 79228809577bf65c75d8e2190f40a7201a6ea3c06521017107206ac82d8c47d5
  • 51159f622351a896439f605349301395c84cb68c245230ec76767e906d295391
  • 3268341dc59e2486672e22c8645046098b6280ad89d4a872ef98e649e2c5cd07
  • 3f480d98a3d7d793152be1393e74c8d7ebbce67c94a6ca968b292389422e7f12
  • 3182309746d206db5eadb8743160bf802e012ea70dfa5ee39120e0494532098f
  • 1fd8c22a0bda1df277545700ac42183447ee3657f5106c9fccee623978a5b594
  • 22e64e7ec0056a4bbeeab7acb3d46ef796c5256c9c934369ad29c35a1df050eb
  • 129df778cde4bb19049d9f48bfaaabf7baec541072dd64c0024b55d63e793a9f
  • 0d8d1243844659f2b7eb7f0c7bec3057c05a0e3731f8330112b6d04dad718528
  • 0d7b4a1d4558e0c6d29bc9a83f20db350f5afe6666942a372ec9a97003365a2d
  • 0e63cc926ac72c4e65eba76f06cbfaabe95623701432c5fe67d1fe00663fba9d
  • 0c8c4b93170a8de7c857c5f4030c6a1e2394940bbd3d48f100014b3d0c64ed90
  • 0875b075f3a9da3d345e0a2b922a134baa0cbf2eaf5754da2a75d2dab2341d13
  • 021f995ee8c497810ec3eecda6f87ed30ecb42ba7f22d32856b1efa231ae274b
  • alexandra.geyer@froid-chaud-service.com
  • stauffer.bluetrait.io
  • sogetis.bluetrait.io
  • mitnick.bluetrait.io
  • revilox.bluetrait.io
  • moduleadobeu.bluetrait.io
  • massen.bluetrait.io
  • managerbank.bluetrait.io
  • manage.opti-tune.com
  • lerelaisvoyages.bluetrait.io
  • leferry.bluetrait.io
  • groupe.bluetrait.io
  • altrotech.bluetrait.io
  • agent.fleetdeck.io

Additional Informations

  • Construction
  • Energy
  • Finance
  • Government
  • Luxembourg
  • Netherlands
  • France