{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/pdq/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Acronis Cyber Protect Connect","AeroAdmin","AnyDesk","APC Admin","Atera Agent","AweSun","Barracuda RMM","BeyondTrust Remote Support","CloudRadial","ConnectWise Automate","Devolutions Remote Desktop Manager","Domotz Agent","DWService","GetScreen","GoToAssist","HelpWire","ImmyBot","Impero","ISL Online","JumpCloud Agent","Kaseya VSA","Komari Agent","Level Agent","LogMeIn Rescue","Lunixar","ManageEngine Remote Access Plus","MeshCentral","Mikogo","Nezha Agent","NinjaOne RMM","Parsec","PDQ Connect","Pulseway","Quick Assist","Radmin","RealVNC","Remotely","RemotePC","Remote Utilities","RPCSuite","RemoteView","RustDesk","SimpleHelp","Splashtop"],"_cs_severities":["low"],"_cs_tags":["defense-evasion","command-and-control","windows","rmm"],"_cs_type":"advisory","_cs_vendors":["Acronis","AeroAdmin","AnyDesk","APC","Atera","AweSun","Barracuda","BeyondTrust","CloudRadial","ConnectWise","Devolutions","Domotz","DWService","GetScreen","GoTo","HelpWire","ImmyBot","Impero","ISLOnline","JumpCloud","Kaseya","Komari","Level","LogMeIn","Lunixar","ManageEngine","MeshCentral","Mikogo","Nezha","NinjaOne","Parsec","PDQ","Pulseway","Microsoft","Radmin","RealVNC","Remotely","RemotePC","RemoteUtilities","RPCSuite","Rsupport","RustDesk","SimpleHelp","Splashtop"],"content_html":"\u003cp\u003eSecurity analysts have observed an increase in threat actors leveraging legitimate Remote Monitoring and Management (RMM) tools as a primary means of establishing persistent, unauthorized remote access to victim environments. Attackers often deliver these tools through social engineering campaigns, where users are induced to download and run seemingly benign MSI installers from the internet. When executed, these packages deploy various RMM agents that grant the actor full administrative control over the compromised endpoint.\u003c/p\u003e\n\u003cp\u003eBecause RMM tools are dual-use software, their presence is not inherently malicious, complicating detection efforts. This intelligence focuses on identifying the specific activity chain where a file of type .msi, originating from a non-reputable internet location, is executed via the Windows Installer process (msiexec.exe), followed shortly by the creation of known RMM-related service or agent executables. Defenders should treat such sequences as potential unauthorized persistence attempts, particularly when the installation was not initiated through managed IT or internal software distribution channels.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of RMM tools by unauthorized actors leads to complete loss of confidentiality and integrity on the impacted host. Attackers use these tools for file exfiltration, remote command execution, and as a springboard for further lateral movement within corporate networks. These campaigns have been observed across various sectors as attackers aim to maintain long-term, stealthy access to internal resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should implement monitoring for the specific sequence of MSI execution followed by RMM agent creation.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided ESQL detection logic to identify the correlation between internet-sourced MSI downloads and RMM binary creation.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for authorized IT RMM deployment to differentiate legitimate administrative activity from unauthorized installations.\u003c/li\u003e\n\u003cli\u003eBlock or monitor downloads from untrusted domains that frequently host these installers, particularly those outside of known developer artifact and cloud storage services.\u003c/li\u003e\n\u003cli\u003eAudit endpoint logs to verify the parent process for all msiexec.exe executions to ensure they align with established software deployment policies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T12:54:37Z","date_published":"2026-09-14T12:54:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rmm-installation-msi/","summary":"This detection identifies the download and execution of Windows Installer (MSI) packages from the internet that result in the installation of remote monitoring and management (RMM) software used for persistent system access.","title":"Detection of RMM Software Deployment via Internet-Originated MSI Files","url":"https://feed.craftedsignal.io/briefs/2026-09-rmm-installation-msi/"}],"language":"en","title":"CraftedSignal Threat Feed - PDQ","version":"https://jsonfeed.org/version/1.1"}