Rapid7 reported multiple intrusions tied to an ongoing social-engineering campaign that starts with email bombing and follow-up calls, often over Microsoft Teams, to pressure users into installing AnyDesk. In the observed June 2024 cases, the operators moved away from earlier Quick Assist and batch-script tradecraft and instead used a signed .NET credential harvester, AntiSpam.exe, followed by payloads masquerading as software updates. Those payloads included SystemBC, Golang HTTP beacons, SOCKS proxy implants, a PowerShell proxy script, reverse SSH tunnels, and Level RMM for persistence and lateral movement, with several binaries signed by the same certificate to appear legitimate.
Rapid7 said one payload, update6.exe, attempted to exploit CVE-2022-26923 to add a machine account for privilege escalation on vulnerable domain controllers, then moved to Kerberoasting by requesting Kerberos service tickets tied to service principal names and cracking them offline to recover service-account credentials. That technique can provide valid account access and support further privilege escalation, persistence, and lateral movement inside Windows domains. Rapid7 published indicators of compromise and urged defenders to use application allowlisting, block unapproved remote monitoring and management tools and related domains, train users to resist help-desk impersonation, and patch systems exposed to CVE-2022-26923.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Rapid7 disclosed the campaign's updated tradecraft, malware details, indicators of compromise, and defensive recommendations including allowlisting, blocking unapproved RMM tools and related domains, user awareness training, and patching CVE-2022-26923.
Rapid7 identified multiple intrusion attempts on June 20, 2024 that matched an ongoing social-engineering campaign using email bombing and follow-up calls, often via Microsoft Teams, to convince users to install AnyDesk. In these newer intrusions, the actors had shifted away from earlier Quick Assist tradecraft.
Rapid7 observed update6.exe attempting to exploit CVE-2022-26923 by adding a machine account when a vulnerable domain controller was present. The technique was then used for privilege escalation and Kerberoasting in affected environments.
After harvesting credentials, the actors executed multiple disguised payloads including SystemBC, Golang HTTP beacons, SOCKS proxy implants, a PowerShell proxy script, reverse SSH tunnels, and the Level RMM tool. Rapid7 also noted many of the compiled payloads were code-signed with shared certificates, indicating coordinated malware development.
In the recent cases Rapid7 analyzed, the threat actors replaced a prior credential-harvesting batch script with a signed .NET executable named AntiSpam.exe. The malware prompted users for credentials, validated them, and collected system and user-account enumeration data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.