Threat Actors Abuse Action1 RMM Tool via Phishing Campaign
Attackers are leveraging the Action1 Remote Management and Monitoring (RMM) platform by distributing malicious PDFs that redirect to VBS files, ultimately installing the RMM agent for persistence and control.

A concerning trend of threat actors abusing Remote Management and Monitoring (RMM) tools continues, with recent activity highlighting the exploitation of the Action1 RMM platform. This campaign follows similar patterns observed with other RMM solutions, where attackers leverage legitimate tools for malicious purposes.
The initial vector for this attack is a phishing email containing a seemingly innocuous PDF invoice. However, upon opening the PDF, users are not presented with invoice details but are instead redirected to a malicious Visual Basic Script (VBS) file. This redirection is achieved through embedded 'OpenAction' and 'URI' keywords within the PDF, a technique designed to bypass email security filters that might flag direct URLs.
The VBS script itself is straightforward and lacks obfuscation. Its primary function is to download and execute a subsequent payload, which in this case is an MSI archive containing the Action1 RMM agent. As a decoy, the VBS script also displays a non-blurred version of the original PDF invoice, attempting to further mask the malicious activity from the user.
Analysis of the downloaded MSI file reveals it contains several components, including executables and DLLs, which are part of the Action1 RMM tool. These components are signed with a certificate from 'Action1 Corporation,' though it is noted that this certificate expired in May 2026. The RMM tool is installed as a service named 'A1Agent' (Action1 Agent), with the main executable located at C:\Windows\Action1\action1_agent.exe.
The installation establishes persistence by registering the agent as a Windows service. Configuration details, including CustomerID, Certificate, and PrivateKey, are stored in the registry under HKLM\Software\Action1\Agent. The agent then connects to Action1's infrastructure, specifically server[.]na-2.action1[.]com, using a CustomerID of 49b18106-681d-456a-b098-092e2818c09a.
This exploitation highlights a common tactic where threat actors abuse the cloud infrastructure of legitimate RMM providers. It is highly probable that attackers are utilizing compromised or free/trial accounts provided by Action1 to deploy and manage the agent on victim systems. This allows them to leverage the RMM tool's built-in functionalities for remote access, command and control, and maintaining persistence without needing to deploy custom malware.
The implications of this attack are significant, as RMM tools are designed for administrative access and can provide attackers with deep control over compromised systems. The use of Action1, a legitimate and widely used RMM solution, further complicates detection and response efforts, as security teams may initially overlook traffic associated with such tools.
Organizations utilizing Action1 or similar RMM solutions should be vigilant for signs of compromise, review their security configurations, and ensure that only authorized personnel are using these tools. Promptly investigating any unusual activity related to RMM agent installations or communications is crucial to mitigating the risks posed by this evolving threat.