Monday, June 8, 2026
  • Subscribe
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us
  • Contact
Data Centres Africa
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Editorial Features 2026
No Result
View All Result
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Editorial Features 2026
No Result
View All Result
Networking+
No Result
View All Result
Home Sectors Business Continuity

KnowBe4 warns of phishing campaign using legitimate remote management tools and stolen credentials

January 26, 2026
Reading Time: 2 mins read
KnowBe4 warns of phishing campaign using legitimate remote management tools and stolen credentials
Share on LinkedInShare on Twitter


KnowBe4 Threat Labs has uncovered a sophisticated phishing campaign that employs stolen login credentials and legitimate Remote Monitoring & Management (RMM) software to gain persistent access to corporate networks. The campaign avoids traditional malware delivery and blends seamlessly into normal IT operations.

The attack operates in two phases. First, attackers send convincing emails that mimic routine workplace communications, such as invitations or notifications. These direct recipients to spoofed sign-in pages that resemble legitimate services, where victims enter their real credentials. The attackers then use these credentials to log into systems through standard channels, reducing the chances of detection.

In the second phase, they deploy RMM tools—specifically GoTo Resolve and LogMeIn—to establish ongoing remote access. These tools are configured for unattended operation, allowing them to run quietly in the background. The attackers used signed software, such as “GreenVelopeCard.exe,” which is legitimately signed by GoTo Technologies USA, LLC, helping bypass reputation-based security checks. They seek elevated permissions through modifications to Windows services and hidden scheduled tasks, designed to evade detection.

The campaign leverages official infrastructure associated with the RMM products, including domains like “dumpster.console.gotoresolve.com” and “dumpster.dev01-console.gotoresolve.com,” along with fallback domains such as “settings.cc.” The use of legitimate, encrypted HTTPS traffic and expected domain names makes malicious activity difficult to distinguish from normal operations.

KnowBe4 recommends organizations monitor for unauthorized installation or use of trusted RMM tools, abnormal remote access activity, unexpected changes in Windows service configurations, and other indicators of compromise. The company emphasizes that attackers increasingly rely on legitimate services, making user behavior and anomaly detection vital. As techniques evolve, defenders should expect continued use of RMM tools in attack chains and update their detection strategies accordingly.

This campaign highlights the importance of enhanced monitoring, user awareness, and incident response to combat sophisticated, stealthy cyber threats.

Related Posts

AI is reshaping jobs faster than companies are reshaping work
Business Continuity

AI is reshaping jobs faster than companies are reshaping work

June 5, 2026
AI investment boom across the UK is fuelled more by fear of missing out than actual results, new research finds
Cloud & Virtualisation

AI investment boom across the UK is fuelled more by fear of missing out than actual results, new research finds

June 4, 2026
Infoblox launches Infoblox IQ to power the next era of agentic AI operations for networking and security
Featured

Infoblox launches Infoblox IQ to power the next era of agentic AI operations for networking and security

June 4, 2026
Absolute Security unveils Lenovo ThinkShield TraceLock, helping customers secure and control Offline PCs 
Security

Absolute Security unveils Lenovo ThinkShield TraceLock, helping customers secure and control Offline PCs 

June 4, 2026

Subscribe

Get the latest networking news and insights delivered to your inbox.

SIGN UP

READ THE LATEST ISSUE

Networking+ is the premier independent resource for communications, network, IT, and data centre professionals. We provide an in-depth look at the rapidly evolving digital infrastructure landscape, covering everything from fixed and wireless LANs to complex enterprise WANs and MANs across both the public and private sectors.

By delivering breaking news, expert analysis, and strategic insights across our print publication, website, and e-newsletters, Networking+ offers a powerful, ‘one-stop’ media combination. Our multi-channel platform is dedicated to keeping industry decision-makers connected, informed, and equipped to future-proof their networks.

Follow Us

Content

  • Magazine
  • Sectors
  • Subscribe
  • Editorial
  • Advertise
  • About Us
  • Features List
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions

© 2026 Networking+ - A Denyan Media Ltd Publication.

No Result
View All Result
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us

© 2026 Networking+ - A Denyan Media Ltd Publication.

We use cookies to analyse site traffic and improve your experience with the latest data centre insights. By clicking 'I Agree', you consent to our use of cookies in accordance with our Privacy Policy.