More than 900 organizations have been targeted by a highly convincing phishing attack which sought to deploy a legitimate remote monitoring and management (RMM) solution and gain access to target endpoints without raising any alarms.The goal was to get the victims to install ConnectWise ScreenConnect, a legitimate IT tool repurposed for full remote access. Instead of stealing passwords, attackers lure victims into giving them administrator-level control over corporate systems. Once inside, they launch account takeovers, lateral phishing campaigns, and data theft while blending in with normal IT activity.This campaign highlights a dangerous shift, Abnormal believes. Instead of breaking into systems, threat actors are now weaponizing trusted workplace tools to sidestep defenses. Should we abandon the online meetings ?

