← Back to feed
Threat Actors & CampaignsEmerging1 sourceApr 11, 2026 · 07:00via The CyberWire

A wolf in admin clothing. [Research Saturday]

Brief

Today we are joined by Selena Larson , Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building , talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat."

Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month.

The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities.

Read more on The CyberWire