Fake Agreements Hide RMM Backdoors as “Normal IT”

Help Net Security · High sophistication
Last updated October 5, 2026

Huntress reports attackers are increasingly installing legitimate remote monitoring and management (RMM) tools after a phishing click, giving them persistent remote control that can blend in with normal IT activity. The article also describes common identity-focused schemes like hidden mailbox rules for invoice fraud and adversary-in-the-middle token theft that bypasses MFA prompts. It includes several practical lures, fake service agreements, device-code login prompts, and fake downloads, that can be used for security awareness simulations.

How the attack worked

According to Huntress, legitimate remote monitoring and management (RMM) software was involved in 45% of endpoint-related incidents the firm recorded in Q1 2026. The entry point is often mundane: a phishing email disguised as a service agreement asks the recipient to review or sign a document. One click installs an RMM tool, and in one documented case, a single click led to an attacker installing Tiflux and then stacking UltraVNC, Splashtop, and ScreenConnect on the same device, giving multiple paths back into the environment from one initial compromise.

The same reporting describes two other identity-focused schemes. In mailbox manipulation, an attacker already inside an inbox creates a hidden rule that routes a vendor's replies to a folder like Archive, then swaps in an altered invoice that redirects payment. Separately, adversary-in-the-middle attacks intercept Microsoft 365 session tokens, letting an attacker remain signed in without a password or an MFA prompt. Device code phishing works similarly: a fake workflow prompt sends a victim to Microsoft's real device code login, and once the code is entered, the attacker holds an access token that can survive a password reset.

Why it succeeded

Each of these techniques exploits trust in something that looks ordinary. RMM tools are the same software IT teams use every day, so remote command execution through them looks like normal administrator work. Mailbox rules are an everyday productivity feature, so a rule quietly diverting vendor replies rarely draws attention. Device code logins are a real Microsoft sign-in mechanism, so victims are completing a legitimate-looking workflow, not an obviously fake login page.

What to watch for

  • Unexpected "service agreements" or shared documents that require a click to review
  • Multiple remote access tools appearing on a device shortly after a single click
  • Payment or remittance details changing mid-thread without verification
  • Vendor replies that seem to stop arriving or go missing
  • Being asked to enter a device code you did not request, outside normal sign-in steps

How to build resistance

  • Treat unsolicited agreements and shared documents as potential installation traps and report rather than click
  • Maintain an allow-list of approved RMM tools and investigate any unapproved tool immediately
  • Require finance and accounts payable staff to verify invoice or bank-detail changes through a known phone number or vendor portal, not through email alone
  • Train employees to recognize that session-token theft and device-code tricks can bypass passwords and MFA prompts, and to report unexpected login workflows

These patterns show that high-impact access often starts with an ordinary-looking click, not an obviously malicious one.

Key findings

  • Huntress observed legitimate RMM software involved in 45% of endpoint-related incidents it recorded in Q1 2026, making RMM abuse a frequently seen, high-impact tactic.
  • A single phishing click can install multiple remote access tools; one example used a fake service agreement to install Tiflux and then added UltraVNC, Splashtop, and ScreenConnect.
  • Mailbox manipulation can hide vendor replies via inbox rules (e.g., sending messages to “Archive”) and enable invoice swapping to redirect payments.
  • Adversary-in-the-middle (AiTM) attacks can steal Microsoft 365 session tokens so attackers remain signed in without needing a password or triggering MFA prompts.
  • Device code phishing can trick users into entering a code on Microsoft’s real device code login, giving the attacker an access token that may survive a password reset.
  • The article notes a case of AI-platform abuse where a malicious Claude Artifact hosted on the real claude.ai domain was used to deliver SectopRAT.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security team, Finance / Accounts Payable, Procurement, Executives.
  • Affected industries: IT services, Professional services, Any organization using Microsoft 365, Finance and accounting functions (invoice payment workflows).
  • Attack channels: email, website.
  • Impersonated: A vendor or service provider sending a “service agreement”, A legitimate vendor (invoice/payment thread hijack), Microsoft 365 login / Microsoft device code sign-in flow.

Red flags to watch for

  • Unexpected “service agreement” that requires a click/open to review
  • Installs remote admin tools that “look like ordinary administrator work”
  • Multiple remote access tools appear on the same device shortly after the click
  • Payment details change mid-thread without verification
  • Missing vendor replies due to messages being routed to a folder like “Archive”
  • Urgency to pay based on an altered invoice
  • Being asked to enter a device code you did not request
  • Login flow happens outside normal single sign-on steps
  • Access gained without the usual MFA prompt/interaction
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does a fake service agreement lead to RMM abuse?

A phishing email disguised as a service agreement prompts a click that installs a legitimate RMM tool like Tiflux, after which attackers can stack additional tools such as UltraVNC, Splashtop, and ScreenConnect on the same device for persistent access.

Why is RMM software abuse hard to detect?

Because RMM tools are the same software IT teams use for legitimate remote management, an attacker's activity through them can look like ordinary administrator work rather than an intrusion.

What is device code phishing and why does it bypass MFA?

A fake workflow prompt directs a victim to Microsoft's real device code login page, and once they enter the attacker-supplied code, the attacker receives an access token that can survive a password reset without triggering an MFA prompt.

How does mailbox manipulation enable invoice fraud?

An attacker already inside an inbox creates a hidden rule routing a vendor's replies to a folder like Archive, then swaps in an altered invoice to redirect payment while the real vendor's messages go unnoticed.

Read the video transcript

You get an email: “Service Agreement – Please Review and Confirm.” Looks routine, right? But one click on that “agreement” can silently install real IT tools like Tiflux, UltraVNC, Splashtop, even ScreenConnect, giving someone remote control that looks like normal admin work. Huntress saw this in 45% of endpoint incidents: one phishing click, several RMM tools, and a backdoor that blends in with real IT. If you didn’t ask for it, that “agreement” is not harmless paperwork. Your move: if you get an unexpected agreement or shared doc, don’t open it, report it to IT or Security so they can check before anyone clicks.

Similar attacks

QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
CSuite Phish Steals M365 Sessions, Installs RMM

CSuite Phish Steals M365 Sessions, Installs RMM

Researchers observed a real phishing campaign (“CSuite”) heavily targeting U.S. organizations using familiar business-themed lures (DocuSign, Adobe, Zoom/Meet, Dropbox, Microsoft 365). After a victim engages, the attackers either steal Microsoft 365 sessions (enabling mailbox takeover and fraud) or…

September 30, 2026
Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

The article describes how real-world phishing and social engineering are evolving to bypass the checks employees are trained to use (bad grammar, suspicious URLs, obvious fake login pages). It highlights specific, observed attack workflows including QR-code “device hop” phishing, OAuth token theft…

September 29, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
M365 Device Code Phishing Bypasses User Suspicion

M365 Device Code Phishing Bypasses User Suspicion

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the…

July 21, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026