N-able is legitimate remote monitoring and management software that threat actors abuse to obtain remote access and persistent control over victim endpoints. It provides endpoint monitoring, patch management, remote access, and script execution. Its use in malicious campaigns does not make the underlying product an intrinsically malicious software family. Attackers exploit the difficulty of distinguishing unauthorized RMM activity from legitimate administration to reduce detection.
Observed delivery methods include phishing emails, document-themed landing pages, and executable installers. One campaign used a batch script masquerading as a DocuSign viewer to install an N-able agent while opening a support page in the browser. Another impersonated the U.S. Internal Revenue Service and linked to a Bitbucket-hosted executable presented as a tax transcript viewer. N-able has also appeared prominently in Portuguese-language phishing campaigns.
N-able is among the RMM tools used by an unnamed cybercriminal cluster targeting trucking carriers, freight brokers, and other logistics businesses. These campaigns use fraudulent freight postings, compromised load boards, hijacked email conversations, and direct phishing to establish access. The attackers use remote access for reconnaissance and persistent control, and deploy separate credential-harvesting tools after compromise. Access to transportation systems supports shipment manipulation and physical cargo theft in collaboration with organized crime groups. Observed batch scripts and executable installation chains target Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-management software weaponized through a malicious batch installer and document-viewer impersonation. Installation occurs alongside a browser redirect intended to deceive the victim. Its settings.Ini file contains an attacker-associated email address.
A legitimate remote monitoring and management tool abused in tax-themed phishing campaigns to gain remote access on victim hosts.
N-able is a legitimate RMM tool abused by threat actors for persistent remote access and control in targeted attacks.
Legitimate RMM tool leveraged by threat actors to establish persistent remote access to compromised systems in the transportation industry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.