Skip to content
Threat Feed

Vendor

NetSupport

4 briefs RSS
medium advisory

Detection of Novel RMM Software Usage

This brief details a detection strategy for identifying the introduction of remote monitoring and management (RMM) software in Windows environments by monitoring for newly observed code-signing certificates.

RMM Software rmm command-and-control windows endpoint-detection
1r 1t
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +46 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 176i updated
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
high advisory

NetSupport Manager Execution from Unusual Path

This rule detects the execution of NetSupport remote access software from non-default paths, potentially indicating an adversary abusing NetSupport Manager for malicious remote control.

NetSupport Manager command_and_control remote_access_tool netsupport
2r 1t