SAINTCON 26 · Session

Your malware infection is just three RMMs in a trenchcoat

Speakers
  • Spike · Principal Threat Intelligence Incident Commander, Huntress Labs

For the better part of the past 20 years, malspam has served the purpose of delivering malware to unsuspecting email recipients. But over the past 18 months, a dramatic change has been taking place: Commercial remote monitoring and management tools (RMMs) have supplanted purpose-built malware as the initial-access deliverable of choice for many threat actors. There are a number of reasons why this is the case, and in this presentation, attendees will be able to see how vibe-coded slop spam and RMMs are becoming the norm for both untargeted attacks and targeted attacks against specific individuals and organizations, with one RMM sometimes delivering multiple other RMMs as payloads as part of complex attack chains, intent to provide as many backdoors as possible.

← Full schedule

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.