{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Attackers use legitimate RMM tools to bypass malware signatures; identifying the phishing-driven delivery phase prevents persistent access before the attacker can stack redundant clients."
      },
      "name": "Rogue RMM Delivery via Trusted Service Phishing",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566",
        "attack.t1203",
        "attack.t1190"
      ],
      "series": {
        "slug": "rogue-rmm-abuse-how-attackers-exploit-remote-access-tools",
        "index": 1,
        "title": "Rogue RMM Abuse: How Attackers Exploit Remote Access Tools",
        "total": 2
      },
      "related": [
        {
          "hunt": "rogue-rmm-persistence-stacking",
          "reason": "This hunt focuses on the delivery phase; a sibling hunt is required to detect the persistent services and redundant client stacking on already-infected hosts.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "Detecting RMM tools is trivial with a single rule, but distinguishing a legitimate IT install from a phishing-driven rogue install requires correlating time-aligned web traffic to lure domains with the arrival of rare binaries on the same endpoint. This hunt provides the cross-surface context necessary to avoid drowning in the noise of approved RMM activity.",
      "coverage": [
        {
          "stage": "phishing-delivery-and-lure",
          "steps": [
            "lure-web-traffic",
            "rare-payload-drops"
          ],
          "status": "covered"
        },
        {
          "stage": "c2-redirect-and-payload-download",
          "steps": [
            "rare-payload-drops"
          ],
          "status": "covered"
        },
        {
          "stage": "rogue-rmm-installation-and-persistence",
          "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-activity",
          "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "redundant-rmm-stacking",
          "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing Delivery and Lure",
            "slug": "phishing-delivery-and-lure",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "TransferXL email",
              "Adobe InDesign lure page",
              "View Document button",
              "ZIP files",
              "Nested PDF lures"
            ]
          },
          {
            "name": "C2 Redirect and Payload Download",
            "slug": "c2-redirect-and-payload-download",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "Attacker-controlled C2 infrastructure",
              "Rogue RMM installer download",
              "ScreenConnect client installer",
              "ITarian client installer"
            ]
          },
          {
            "name": "Rogue RMM Installation and Persistence",
            "slug": "rogue-rmm-installation-and-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "ITarian client installation",
              "ScreenConnect client installation",
              "SYSTEM-level privileges",
              "Persistent remote access service"
            ]
          },
          {
            "name": "Defense Evasion Activity",
            "slug": "defense-evasion-activity",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562"
            ],
            "observables": [
              "HideUL_x64.exe"
            ]
          },
          {
            "name": "Redundant RMM Stacking",
            "slug": "redundant-rmm-stacking",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "Multiple rogue RMM clients",
              "ITarian and ScreenConnect coexistence",
              "Redundant ScreenConnect instances"
            ]
          }
        ],
        "summary": "Threat actors are using phishing emails with lures hosted on legitimate services like TransferXL and Adobe InDesign to trick victims into installing rogue RMM tools like ITarian and ScreenConnect. These tools provide persistent, hands-on control and are often deployed in redundant pairs alongside defense evasion binaries like HideUL_x64.exe to maintain long-term access."
      },
      "severity": "medium",
      "rationale": "Focus the initial run on workstations and servers with no legitimate RMM presence; expand to the whole estate if suspicious downloads are found on a single host.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "scoping",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "Limit analysis to these hosts; leave empty for fleet-wide."
        },
        "lure_domains": {
          "from": {
            "ref": "huntress-rmm-abuse",
            "kind": "article",
            "observed": "2026-09-23"
          },
          "type": "list[domain]",
          "default": [
            "indesign.adobe.com",
            "transferxl.com"
          ],
          "description": "Known lure-hosting domains from the report."
        },
        "rmm_keywords": {
          "from": {
            "ref": "huntress-rmm-abuse",
            "kind": "article",
            "observed": "2026-09-23"
          },
          "type": "list[string]",
          "default": [
            "screenconnect",
            "itarian",
            "connectwise",
            "itarian client",
            "screenconnect client"
          ],
          "description": "Exact software names or keywords to identify RMM clients."
        },
        "lookback_days": {
          "from": {
            "ref": "default-retention",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access",
          "name": "Huntress \u2014 Rogue RMM Abuse: How Attackers Exploit Remote Access Tools"
        }
      ],
      "blind_spots": [
        {
          "id": "proxy-encryption-blind-spot",
          "risk": "Attackers can hide lure-specific URL paths within encrypted traffic to trusted domains.",
          "stage": "phishing-delivery-and-lure",
          "question": "whether the specific 'View Document' button was clicked within an encrypted Adobe session",
          "requires": "TLS inspection on web proxies"
        },
        {
          "id": "renamed-installer-blind-spot",
          "risk": "A renamed binary will bypass the keyword-based file activity query.",
          "stage": "c2-redirect-and-payload-download",
          "question": "whether an RMM installer was renamed to a generic name like 'update.exe' to avoid keyword detection",
          "requires": "file hashing and reputation services"
        }
      ]
    },
    "name": "Rogue RMM Delivery via Trusted Service Phishing",
    "description": "This hunt identifies the early stages of RMM abuse where attackers use legitimate document-sharing platforms to deliver installers. It correlates web-based lure visits on Adobe and TransferXL with the subsequent arrival of RMM-related binaries on the same endpoints. By identifying these transitions, the hunt distinguishes unauthorized rogue RMM deployments from legitimate IT operations. An agent weighs the timing and rarity of these events to confirm an intrusion."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "rogue-rmm-abuse-how-attackers-exploit-remote-access-tools",
          "index": 1,
          "title": "Rogue RMM Abuse: How Attackers Exploit Remote Access Tools",
          "total": 2
        },
        "coverage": [
          {
            "stage": "phishing-delivery-and-lure",
            "steps": [
              "lure-web-traffic",
              "rare-payload-drops"
            ],
            "status": "covered"
          },
          {
            "stage": "c2-redirect-and-payload-download",
            "steps": [
              "rare-payload-drops"
            ],
            "status": "covered"
          },
          {
            "stage": "rogue-rmm-installation-and-persistence",
            "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-activity",
            "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "redundant-rmm-stacking",
            "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.",
        "blind_spots": [
          {
            "id": "proxy-encryption-blind-spot",
            "risk": "Attackers can hide lure-specific URL paths within encrypted traffic to trusted domains.",
            "stage": "phishing-delivery-and-lure",
            "question": "whether the specific 'View Document' button was clicked within an encrypted Adobe session",
            "requires": "TLS inspection on web proxies"
          },
          {
            "id": "renamed-installer-blind-spot",
            "risk": "A renamed binary will bypass the keyword-based file activity query.",
            "stage": "c2-redirect-and-payload-download",
            "question": "whether an RMM installer was renamed to a generic name like 'update.exe' to avoid keyword detection",
            "requires": "file hashing and reputation services"
          }
        ],
        "scoping_notes": "Focus the initial run on workstations and servers with no legitimate RMM presence; expand to the whole estate if suspicious downloads are found on a single host.",
        "beyond_detection": "Detecting RMM tools is trivial with a single rule, but distinguishing a legitimate IT install from a phishing-driven rogue install requires correlating time-aligned web traffic to lure domains with the arrival of rare binaries on the same endpoint. This hunt provides the cross-surface context necessary to avoid drowning in the noise of approved RMM activity."
      }
    },
    {
      "id": "scoping-rmm-software",
      "type": "query",
      "label": "Inventory of existing RMM software",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, vendor_name FROM hb_software_inventory WHERE (instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "surface": "hb_software_inventory",
        "description": "Identify hosts that already have the RMM tools mentioned in the report to provide baseline context for the analyst.",
        "expected_signal": "A list of hosts with matching software; widespread presence usually indicates approved IT tools, while isolated instances warrant closer inspection."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Inventory of existing RMM software",
        "reads": [
          "device_hostname",
          "package_name",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, vendor_name FROM hb_software_inventory WHERE (instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(package_name) || ',') > 0 OR instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(vendor_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with matching software; widespread presence usually indicates approved IT tools, while isolated instances warrant closer inspection.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "lure-web-traffic",
      "type": "query",
      "label": "Lure web traffic",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Find connections to the trusted domains hosting the malicious lures.",
        "expected_signal": "Hosts visiting Adobe or TransferXL domains; zero results suggest the initial phishing link was not clicked."
      },
      "parents": [
        {
          "id": "scoping-rmm-software"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Lure web traffic",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_full",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_full, time FROM hb_http_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "Hosts visiting Adobe or TransferXL domains; zero results suggest the initial phishing link was not clicked.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "rare-payload-drops",
      "type": "query",
      "label": "Rare RMM payload drops",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_name) LIKE '%.exe' OR LOWER(file_name) LIKE '%.msi' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%.pdf') AND (instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR LOWER(file_name) LIKE '%itarian%' OR LOWER(file_name) LIKE '%screenconnect%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING host_count <= 3",
        "surface": "hb_file_activity",
        "description": "Identify RMM installers arriving on disk that are rare across the fleet, suggesting unauthorized installation.",
        "expected_signal": "Rare RMM-themed binaries; common IT updaters appearing on dozens of hosts are ignored."
      },
      "parents": [
        {
          "id": "scoping-rmm-software"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare RMM payload drops",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_file_activity WHERE (LOWER(file_name) LIKE '%.exe' OR LOWER(file_name) LIKE '%.msi' OR LOWER(file_name) LIKE '%.zip' OR LOWER(file_name) LIKE '%.pdf') AND (instr(',' || '{{rmm_keywords}}' || ',', ',' || LOWER(file_name) || ',') > 0 OR LOWER(file_name) LIKE '%itarian%' OR LOWER(file_name) LIKE '%screenconnect%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name, file_path HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "Rare RMM-themed binaries; common IT updaters appearing on dozens of hosts are ignored.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_name",
            "file_path"
          ],
          "rare_below": 4
        },
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "triage-delivery-chain",
      "type": "analytic",
      "label": "Triage RMM delivery chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "scoping-rmm-software",
          "lure-web-traffic",
          "rare-payload-drops"
        ],
        "objective": "Determine if any host exhibits the phishing-to-RMM-delivery pattern described in the article, specifically visiting a lure domain followed by a rare RMM binary drop.",
        "description": "Correlate the software inventory, lure traffic, and rare file drops to confirm a rogue RMM installation.",
        "max_iterations": 4,
        "expected_signal": "A per-host verdict that confirms whether the lure visit preceded a rare RMM installer download.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing specific rows and time alignment."
      },
      "parents": [
        {
          "id": "lure-web-traffic",
          "kind": "merge"
        },
        {
          "id": "rare-payload-drops",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict is malicious for at least one host",
        "condition": "the triage verdict is malicious for at least one host",
        "blind_spot": "proxy-encryption-blind-spot",
        "confidence": "high",
        "description": "Direct high-confidence hits to containment and lower-confidence hits to manual review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-delivery-chain"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Immediately sever the attacker's remote connection via the rogue RMM.",
        "instructions": "Isolate the endpoint and revoke any active sessions for the user identified in the HTTP logs.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-investigation",
      "type": "task",
      "label": "Forensic investigation",
      "config": {
        "assignee": "analyst",
        "description": "Investigate the isolated host for secondary RMM stacking and persistence.",
        "instructions": "Search for secondary RMM installations (ScreenConnect, ITarian) and defense evasion binaries like HideUL_x64.exe on the host. Verify if the ZIP/PDF lure resulted in execution via hb_process_activity."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "remediation-and-tuning",
      "type": "task",
      "label": "Remediation and tuning",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt by updating RMM inventory and tuning detection rules.",
        "instructions": "Record the findings in the incident report. Update the authorized RMM software inventory to include any newly discovered legitimate tools found during the baseline step."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-investigation"
        }
      ]
    }
  ]
}