Quick Facts

  • TrustConnect malware disguised as legitimate RMM tool costs criminals $300 per month for full system access
  • RMM abuse increased 277% year-over-year in 2025, accounting for 24% of all observed cybersecurity incidents
  • Proofpoint successfully disrupted the operation by getting the malware’s Extended Validation certificate revoked

Cybercriminals created an entirely fake enterprise software company called TrustConnect to sell remote access trojans disguised as legitimate remote monitoring and management tools. Proofpoint discovered the malware-as-a-service operation on February 19, 2026, after the domain was created January 12.

The criminal operation charges $300 monthly for what appears to be legitimate RMM software but actually provides attackers full mouse and keyboard controls, screen recording abilities, file transfer capabilities, command execution, and user account control bypass on infected systems.

Proofpoint researchers noted they “haven’t seen before is criminals building an entirely new product, website and all, that looks legitimate on the surface, but is actually completely malicious.” The malware creator used the domain as a business website designed to convince certificate providers the software was legitimate.

Massive Surge in RMM Abuse

Remote monitoring and management tool abuse exploded 277% year-over-year in 2025, representing 24% of all observed cybersecurity incidents according to Huntress’s 2026 Cyber Threat Report. The company analyzed data from over four million endpoints and nine million identities across 230,000+ organizations worldwide.

Greg Linares, Huntress Principal Threat Intelligence Analyst, said cybercriminals “have evolved into highly efficient operators, running their campaigns like well-oiled businesses.” He noted attackers moved away from flashy exploits toward “simple, effective, and scalable attacks that let them target countless organizations with high success rates.”

Healthcare and technology sectors experienced the largest increases in RMM abuse activity. Education remained the most targeted industry in 2024 with 21% of attacks, followed by healthcare at 17% and technology at 12%.

Distribution and Impact

TrustConnect spread through phishing emails in English and French, including tax-related messages, DocuSign notifications, and meeting invitations. The malware created fake installers mimicking familiar software like Zoom, Microsoft Teams, Adobe Reader, and Google Meet.

Proofpoint attributed TrustConnect with moderate confidence to a Redline infostealer customer based on Telegram handle analysis connected to Operation Magnus, the October 2024 law enforcement takedown of Redline and META malware operations.

Cybercrime costs are projected to reach $12.2 trillion annually by 2031, making it the world’s third-largest economy. The average global data breach cost reached $4.88 million in 2024, representing a 10% increase from 2023.

Proofpoint worked with industry partners to disrupt the TrustConnect operation by revoking its Extended Validation code-signing certificate on February 6, 2026. However, files signed before revocation remained valid, highlighting the persistent nature of such threats.

Read more: Who’s watching who? Experts reveal criminals using fake enterprise software to gain access to company systems

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.