Episode

A wolf in admin clothing.

Podcast
Research Saturday
Published
Apr 11, 2026
Duration seconds
1484
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/420/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW8774977559.mp3?updated=1775842418
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/a-wolf-in-admin-clothing
Markdown
/podcast/research-saturday-1377435/a-wolf-in-admin-clothing.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/a-wolf-in-admin-clothing/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/a-wolf-in-admin-clothing.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month. The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools. The research and executive brief can be found here: (Don't) TrustConnect: It's a RAT in an RMM hat