Wednesday, September 9, 2026
  • Subscribe
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us
  • Contact
Networking+
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
No Result
View All Result
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
No Result
View All Result
Networking+
No Result
View All Result
Home Technologies Business Continuity

KnowBe4 warns of phishing campaign using legitimate remote management tools and stolen credentials

January 26, 2026
Reading Time: 2 mins read
KnowBe4 warns of phishing campaign using legitimate remote management tools and stolen credentials
Share on LinkedInShare on Twitter


KnowBe4 Threat Labs has uncovered a sophisticated phishing campaign that employs stolen login credentials and legitimate Remote Monitoring & Management (RMM) software to gain persistent access to corporate networks. The campaign avoids traditional malware delivery and blends seamlessly into normal IT operations.

The attack operates in two phases. First, attackers send convincing emails that mimic routine workplace communications, such as invitations or notifications. These direct recipients to spoofed sign-in pages that resemble legitimate services, where victims enter their real credentials. The attackers then use these credentials to log into systems through standard channels, reducing the chances of detection.

In the second phase, they deploy RMM tools—specifically GoTo Resolve and LogMeIn—to establish ongoing remote access. These tools are configured for unattended operation, allowing them to run quietly in the background. The attackers used signed software, such as “GreenVelopeCard.exe,” which is legitimately signed by GoTo Technologies USA, LLC, helping bypass reputation-based security checks. They seek elevated permissions through modifications to Windows services and hidden scheduled tasks, designed to evade detection.

The campaign leverages official infrastructure associated with the RMM products, including domains like “dumpster.console.gotoresolve.com” and “dumpster.dev01-console.gotoresolve.com,” along with fallback domains such as “settings.cc.” The use of legitimate, encrypted HTTPS traffic and expected domain names makes malicious activity difficult to distinguish from normal operations.

KnowBe4 recommends organizations monitor for unauthorized installation or use of trusted RMM tools, abnormal remote access activity, unexpected changes in Windows service configurations, and other indicators of compromise. The company emphasizes that attackers increasingly rely on legitimate services, making user behavior and anomaly detection vital. As techniques evolve, defenders should expect continued use of RMM tools in attack chains and update their detection strategies accordingly.

This campaign highlights the importance of enhanced monitoring, user awareness, and incident response to combat sophisticated, stealthy cyber threats.

Related Posts

West Sussex advances smart livestock monitoring with Pneumonitor and Boldyn Networks’ private 5G
Wireless LAN & WAN

West Sussex advances smart livestock monitoring with Pneumonitor and Boldyn Networks’ private 5G

September 1, 2026
UK to use Ukraine battlefield data to train AI to protect military sites and critical infrastructure
Security

UK to use Ukraine battlefield data to train AI to protect military sites and critical infrastructure

September 1, 2026
Pulsant unveils £1m investment in Birmingham data centre
Data Centres

Pulsant unveils £1m investment in Birmingham data centre

September 1, 2026
Openreach plans for wider UK rollout of Next Gen Full Fibre
Fixed LAN & WAN

Openreach plans for wider UK rollout of Next Gen Full Fibre

September 1, 2026

Subscribe

Get the latest networking news and insights delivered to your inbox.

SIGN UP

READ THE LATEST ISSUE

Networking+ is the premier independent resource for communications, network, IT, and data centre professionals. We provide an in-depth look at the rapidly evolving digital infrastructure landscape, covering everything from fixed and wireless LANs to complex enterprise WANs and MANs across both the public and private sectors.

By delivering breaking news, expert analysis, and strategic insights across our print publication, website, and e-newsletters, Networking+ offers a powerful, ‘one-stop’ media combination. Our multi-channel platform is dedicated to keeping industry decision-makers connected, informed, and equipped to future-proof their networks.

Follow Us

Content

  • Magazine
  • Technologies
  • Subscribe
  • Editorial
  • Advertise
  • About Us
  • Features List
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions

© 2026 Networking+ - A Denyan Media Ltd Publication.

No Result
View All Result
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us

© 2026 Networking+ - A Denyan Media Ltd Publication.

We use cookies to analyse site traffic and improve your experience with the latest enterprise networking insights. By clicking 'OK', you consent to our use of cookies in accordance with our Privacy Policy.