216.73.216.6

(Don't) TrustConnect: It's a RAT in an RMM hat

· Published 19/02/2026 11:10 · Modified 19/02/2026 12:44

Export JSON

Essential information

Published
19/02/2026 11:10
Modified
19/02/2026 12:44
Tags
2026-02-19 c2 infrastructure cybercrime digital signatures docconnect email campaigns malware-as-a-service remote access trojan rmm abuse trustconnect trustconnect rat
Related entities
10 observables, 5 techniques (mitre), 2 malware, 10 others

Description

A new (MaaS) called has been discovered masquerading as a legitimate remote monitoring and management (RMM) tool. The malware, classified as a (RAT), uses a fake business website as its command and control center and MaaS portal. Priced at $300 per month, it offers features like a web-based C2 dashboard, automated payload generation with , and remote desktop capabilities. The malware has been distributed through various , often alongside legitimate RMM tools. Proofpoint researchers identified links between 's creator and previous users of Redline stealer. The emergence of this new MaaS demonstrates the ongoing evolution of the market and the thriving ecosystem of .

External references