Episode

Two RMMs walk into a phish…

Podcast
Research Saturday
Published
Nov 22, 2025
Duration seconds
1440
Processing state
failed
Canonical source
https://thecyberwire.com/podcasts/research-saturday/403/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW6550795623.mp3?updated=1763755723
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/two-rmms-walk-into-a-phish
Markdown
/podcast/research-saturday-1377435/two-rmms-walk-into-a-phish.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/two-rmms-walk-into-a-phish/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/two-rmms-walk-into-a-phish.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Alex Berninger, Senior Manager of Intelligence at Red Canary, and Mike Wylie, Director, Threat Hunting at Zscaler, join to discuss four phishing lures in campaigns dropping RMM tools. Red Canary and Zscaler uncovered phishing campaigns delivering legitimate remote monitoring and management (RMM) tools—like ITarian, PDQ, SimpleHelp, and Atera—to gain stealthy access to victim systems. Attackers used four main lures (fake browser updates, meeting invites, party invitations, and fake government forms) and often deployed multiple RMM tools in quick succession to establish persistent access and deliver additional malware. The report highlights detection opportunities, provides indicators of compromise, and stresses the importance of monitoring authorized RMM usage, scrutinizing trusted services like Cloudflare R2, and enforcing strict network and endpoint controls. The research can be found here: You’re invited: Four phishing lures in campaigns dropping RMM tools Learn more about your ad choices. Visit megaphone.fm/adchoices