Tommy Madjar

@ffforward.bsky.social

Threat Researcher @ Proofpoint. Opinions are my own etc

Proofpoint threat researchers identified a new malware-as-a-service named #TrustConnect. Notably, it masquerades as a legitimate remote monitoring and management tool, marking an evolution in how attackers weaponize trust around enterprise tooling. See our blog for details: brnw.ch/21x05Vh.

(Don't) TrustConnect: It's a RAT in an RMM hat | Proofpoint US

Key findings  Proofpoint observed a new malware-as-a-service (MaaS) masquerading as a legitimate remote monitoring and management (RMM) tool. It calls itself TrustConnect.

brnw.ch

Since 14 October, we’ve tracked a high volume XWorm campaign targeting Germany. The activity is attributed to TA584, a sophisticated #cybercrime group tracked since 2020. Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.

Bild

New ecrime insights: TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns. Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.

This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case. 1/2

Bild

Proofpoint also recently observed this activity delivering GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.

Researcher for Gootloader malware@gootloader.zip · last yr.

⚠️ New TTPs detected for #Gootloader ⚠️ Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning. gootloader.wordpress.com/2025/03/31/g...