Threat Actors Using Fake Notepad++ and 7-zip Websites to Deploy Remote Monitoring Tools
Recent observations highlight that cybercriminals are increasingly deploying malicious Remote Monitoring and Management (RMM) tools through counterfeit websites that imitate popular software download pages. These deceptive platforms impersonate…
Recent observations highlight that cybercriminals are increasingly deploying malicious Remote Monitoring and Management (RMM) tools through counterfeit websites that imitate popular software download pages. These deceptive platforms impersonate legitimate utilities such as Notepad++ and 7-Zip, misleading users into downloading remote access tools like LogMeIn Resolve instead of the desired software.
Upon installation, these RMM tools enable attackers to gain full control over compromised systems, execute remote commands, and potentially deploy additional malware payloads such as PatoRAT. The initial infection often occurs when users visit these fraudulent download sites, frequently accessed via advertisements or manipulated search engine results.
These counterfeit websites replicate the appearance and layout of official software distribution sites, complicating detection for average users. When users attempt to download Notepad++ or 7-Zip, the sites instead provide LogMeIn Resolve or PDQ Connect. Although these are legitimate remote management tools, they are repurposed by attackers for unauthorized activities.
Once installed, these tools establish a persistent connection through their respective infrastructures, which threat actors exploit to maintain system access. Analysts have noted a significant increase in the use of RMM tools during the initial infection phases. Unlike traditional malware, these legitimate applications often evade antivirus detection, posing a substantial challenge for security teams.
These counterfeit websites replicate the appearance and layout of official software distribution sites, complicating detection for average users.
Infection Mechanism and Remote Access Deployment
The infection relies on social engineering techniques that exploit user trust in familiar software brands. Fake websites display convincing download buttons, version numbers, and installation options that mimic legitimate pages. Users, therefore, inadvertently install LogMeIn Resolve or PDQ Connect instead of the expected software.
These RMM tools offer features such as remote support and patch management, typically designed for IT administrators but misused by attackers for unauthorized access. After installation, the tools register with their cloud-based management infrastructure, enabling attackers to connect without additional authentication. Threat actors may then execute PowerShell commands to install PatoRAT, a backdoor that secures persistent access even if the RMM tool is removed later.
Users are advised to download software exclusively from official websites and verify digital signatures and certificates before installation. Organizations should deploy endpoint detection and response solutions capable of monitoring RMM tool activity and identifying suspicious remote access patterns indicative of potential compromise.
Based on reporting by Cyber Security News.
