# Initial Access

Published articles for Initial Access.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Phishing Abuses RMM Tools for Persistent Access

DevFeed: [Phishing Abuses RMM Tools for Persistent Access](<https://devfeed.tech/articles/phishing-abuses-rmm-tools-for-persistent-access-62309.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/>)

Author: Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts

Published: 2026-09-29T21:39:27Z

Content type: news

Language: en

Sources: [Microsoft Security](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>)

Tags: [follow](<https://devfeed.tech/tags/follow.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Microsoft reports phishing campaigns that delivered a disguised MSP360 remote-management installer and used it to install ConnectWise ScreenConnect. The two tools created redundant remote-access channels for persistent access and follow-on activity, including information collection and credential-access operations.

### Source excerpt

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

## RemoteThreat Launches With $7 Million for Offensive Operations Platform

DevFeed: [RemoteThreat Launches With $7 Million for Offensive Operations Platform](<https://devfeed.tech/articles/remotethreat-launches-with-7-million-for-offensive-operations-platform-61751.md>)

Original publisher: [Read original article](<https://www.securityweek.com/remotethreat-launches-with-7-million-for-offensive-operations-platform/>)

Author: SecurityWeek News

Published: 2026-09-29T14:38:07Z

Content type: news

Language: en

Sources: [SecurityWeek](<https://devfeed.tech/sources/securityweek.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai-assistants](<https://devfeed.tech/tags/ai-assistants.md>), [c2](<https://devfeed.tech/tags/c2.md>), [command](<https://devfeed.tech/tags/command.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cybersecurity-funding](<https://devfeed.tech/tags/cybersecurity-funding.md>), [datatribe](<https://devfeed.tech/tags/datatribe.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [funding](<https://devfeed.tech/tags/funding.md>), [general](<https://devfeed.tech/tags/general.md>), [hacker](<https://devfeed.tech/tags/hacker.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [o-c-o-platform](<https://devfeed.tech/tags/o-c-o-platform.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [offensive-cyber-operations](<https://devfeed.tech/tags/offensive-cyber-operations.md>), [offensive-security](<https://devfeed.tech/tags/offensive-security.md>), [operator](<https://devfeed.tech/tags/operator.md>), [osage-university-partners](<https://devfeed.tech/tags/osage-university-partners.md>), [pre-seed](<https://devfeed.tech/tags/pre-seed.md>), [pre-seed-funding](<https://devfeed.tech/tags/pre-seed-funding.md>), [remotethreat](<https://devfeed.tech/tags/remotethreat.md>)

### AI overview

RemoteThreat launched from stealth with $7 million in pre-seed funding to develop an offensive cyber operations platform. Its O/C/O Platform combines mission planning, command and control, implants, access and obfuscation tools, targeting and analysis systems, and AI assistants for enterprise and critical infrastructure red teams, government mission teams, and vetted defense partners. Operations can be manual, AI-assisted, or delegated to autonomous workflows, with policies, approvals, and traceable decisions governing consequential actions.

### Source excerpt

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.

## The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments

DevFeed: [The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments](<https://devfeed.tech/articles/the-infostealer-incursion-how-stolen-credentials-breach-cloud-code-and-ai-environments-60522.md>)

Original publisher: [Read original article](<https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials>)

Author: Shahar Dorfman

Published: 2026-09-25T14:51:15Z

Content type: article

Language: en

Sources: [Wiz](<https://devfeed.tech/sources/wiz-blog-rss-feed.md>)

Topics: [credential-based attacks](<https://devfeed.tech/topics/credential-based-attacks.md>), [Secrets Management](<https://devfeed.tech/topics/secrets-management.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [gcp](<https://devfeed.tech/tags/gcp.md>), [github](<https://devfeed.tech/tags/github.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infostealer](<https://devfeed.tech/tags/infostealer.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [research](<https://devfeed.tech/tags/research.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Wiz Research analyzes NordStellar data to map credentials targeted by infostealer malware and assess their potential impact on cloud, code, and AI environments. The article describes how social engineering and supply chain attacks can steal developers' credentials, API keys, and session tokens, enabling access to cloud estates and code platforms. It also outlines the infostealer ecosystem, from malware services to underground marketplaces and initial access brokers.

### Source excerpt

Wiz Research analyzes NordStellar data to map the credentials targeted by infostealer families and assess their potential impact across cloud, code, and AI environments.

## The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

DevFeed: [The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint](<https://devfeed.tech/articles/the-not-so-silent-miner-threat-actor-compiles-cryptominer-on-the-endpoint-59340.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/threat-actor-compiles-cryptominer>)

Author: Harlan Carvey; Lindsey O'Donnell-Welch

Published: 2026-09-24T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [.NET Framework](<https://devfeed.tech/topics/net-framework.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Monero](<https://devfeed.tech/topics/monero.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [actor](<https://devfeed.tech/tags/actor.md>), [anydesk](<https://devfeed.tech/tags/anydesk.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [cve](<https://devfeed.tech/tags/cve.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [edr](<https://devfeed.tech/tags/edr.md>), [exploited](<https://devfeed.tech/tags/exploited.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-report](<https://devfeed.tech/tags/incident-report.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [installation](<https://devfeed.tech/tags/installation.md>), [it](<https://devfeed.tech/tags/it.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [miner](<https://devfeed.tech/tags/miner.md>), [net-framework](<https://devfeed.tech/tags/net-framework.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [processes](<https://devfeed.tech/tags/processes.md>)

### AI overview

Huntress reports an incident in which attackers exploited a Samsung MagicINFO vulnerability, installed AnyDesk, and compiled a Monero cryptominer directly on a victim endpoint. The compilation activity produced a noticeable spike in EDR telemetry.

### Source excerpt

Threat actors exploited Samsung MagicINFO to install AnyDesk, disable Defender, and compile a Monero miner directly on a victim endpoint. Learn the detection signals.

## US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

DevFeed: [US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks](<https://devfeed.tech/articles/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks-59268.md>)

Original publisher: [Read original article](<https://www.securityweek.com/us-court-sentences-armenian-man-to-prison-for-ryuk-ransomware-attacks/>)

Author: Eduard Kovacs

Published: 2026-09-24T08:38:29Z

Content type: news

Language: en

Sources: [SecurityWeek](<https://devfeed.tech/sources/securityweek.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [2019](<https://devfeed.tech/tags/2019.md>), [2020](<https://devfeed.tech/tags/2020.md>), [2026](<https://devfeed.tech/tags/2026.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [doj](<https://devfeed.tech/tags/doj.md>), [extortion](<https://devfeed.tech/tags/extortion.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [ransomware-attacks](<https://devfeed.tech/tags/ransomware-attacks.md>), [ryuk](<https://devfeed.tech/tags/ryuk.md>), [sentenced](<https://devfeed.tech/tags/sentenced.md>), [uk](<https://devfeed.tech/tags/uk.md>), [ukraine](<https://devfeed.tech/tags/ukraine.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

A US court sentenced Karen Vardanyan to 24 months in federal prison for his role in Ryuk ransomware attacks between 2019 and 2020. He was also ordered to pay more than $1.2 million in restitution after extorting over $1 million from victims.

### Source excerpt

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.

## Rogue RMM Abuse: How Attackers Exploit Remote Access Tools

DevFeed: [Rogue RMM Abuse: How Attackers Exploit Remote Access Tools](<https://devfeed.tech/articles/rogue-rmm-abuse-how-attackers-exploit-remote-access-tools-59339.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access>)

Author: Sarah Reddish; Beth Robinson

Published: 2026-09-23T12:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [remote access](<https://devfeed.tech/topics/remote-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [defensive](<https://devfeed.tech/tags/defensive.md>), [detection](<https://devfeed.tech/tags/detection.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [it](<https://devfeed.tech/tags/it.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

A Huntress SOC investigation describes phishing attacks that tricked employees into installing rogue remote monitoring and management tools, including ITarian and ScreenConnect. Attackers used the tools to gain persistent remote access, add redundant access paths, evade detection, and expand their control within affected environments.

### Source excerpt

The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.

## Ryuk ransomware member sentenced to 24 months in prison

DevFeed: [Ryuk ransomware member sentenced to 24 months in prison](<https://devfeed.tech/articles/ryuk-ransomware-member-sentenced-to-24-months-in-prison-58538.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/>)

Author: Sergiu Gatlan

Published: 2026-09-23T08:20:05Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [armenia](<https://devfeed.tech/tags/armenia.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [cybercriminals](<https://devfeed.tech/tags/cybercriminals.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [initial-access-broker](<https://devfeed.tech/tags/initial-access-broker.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [prison](<https://devfeed.tech/tags/prison.md>), [raas](<https://devfeed.tech/tags/raas.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [ransomware-attacks](<https://devfeed.tech/tags/ransomware-attacks.md>), [ryuk](<https://devfeed.tech/tags/ryuk.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [usa](<https://devfeed.tech/tags/usa.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A Ryuk ransomware participant was sentenced to 24 months in prison and three years of supervised release after pleading guilty to hacking U.S. companies and deploying ransomware. The attacks compromised organizations in multiple states and generated substantial ransom payments. Ryuk operated as a ransomware-as-a-service group from 2018 to 2020 before its successors continued operating under other ransomware brands.

### Source excerpt

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

## DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

DevFeed: [DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer](<https://devfeed.tech/articles/darkme-rat-a-vb6-apt-trojan-turned-conventional-infostealer-58692.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/darkme-rat-abandons-exploits>)

Author: James Northey; Andrew Brandt

Published: 2026-09-22T21:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Visual Basic](<https://devfeed.tech/topics/visual-basic.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [infostealer](<https://devfeed.tech/tags/infostealer.md>), [initial-access](<https://devfeed.tech/tags/initial-access.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [rat](<https://devfeed.tech/tags/rat.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [trojan](<https://devfeed.tech/tags/trojan.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

Huntress examines a DarkMe campaign in which a VB6 remote access trojan and infostealer was delivered through social engineering rather than an exploit. The campaign used a malicious PIF presented as an image, illustrating how threat actors can use simpler initial-access methods.

### Source excerpt

DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.