Attackers continue to use trusted document-signing themes and legitimate remote monitoring and management tools to gain persistent access. The defensive priority is not to ban every RMM product; it is to control which tools can run, who can install them, and how unexpected remote sessions are detected.
Current as of 2026-08-15
BlueVoyant’s original campaign analysis described a DocuSign-themed kit using many domains and redirect gates. Forescout’s SeasonalInvite research and Microsoft’s signed-malware analysis document related abuse patterns.
Decision summary
- Verify signature requests through a known business channel rather than the message link.
- Allowlist approved remote-support tools and block or alert on unauthorized alternatives.
- Treat a valid code signature as identity evidence, not proof that software is safe.
- Correlate email, DNS, endpoint, identity, and remote-session evidence during response.
Recognize the attack chain
- A trusted business theme creates urgency.
- Redirect infrastructure filters victims and hides the final destination.
- The victim downloads or runs a remote-access installer.
- The attacker receives persistent access through legitimate software.
- Credentials and business systems are targeted after the foothold.
Control remote-access software
- Maintain an approved-product and publisher inventory.
- Block unauthorized installers and portable binaries where feasible.
- Restrict local administrator rights.
- Alert on new services, agents, scheduled tasks, and remote sessions.
- Require named technician identities and customer-visible authorization.
- Review vendor access and remove abandoned tools.
Improve message verification
Users should open the known DocuSign or business portal directly, not through an unexpected link. For financial, legal, payroll, or account changes, confirm the sender through a known number or a separate trusted channel.
Respond to an unauthorized RMM installation
- Disconnect or contain the endpoint according to the incident plan.
- Preserve the message, URL chain, file, process, service, and network evidence.
- Terminate remote sessions and remove persistence after evidence collection.
- Reset exposed credentials and revoke sessions based on scope.
- Hunt for the same tool, domain, signer, or behavior across the environment.
For related guidance from ITECS, see ITECS email security services.
Sources and update trigger
- BlueVoyant — DocuSign phishing kit and RMM analysis
- Forescout — SeasonalInvite RMM campaign
- Microsoft Security — Signed malware deploying RMM backdoors
- CISA — Malicious use of legitimate RMM software
Review trigger: Refresh when vendors publish new campaign infrastructure, tools, or detection guidance.
