---
title: "Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access"
url: https://daily.dev/posts/phishing-attack-uses-stolen-credentials-to-install-logmein-rmm-for-persistent-access-oyzsvb4za
source_url: https://thehackernews.com/2026/01/phishing-attack-uses-stolen-credentials.html
type: article
source: "The Hacker News"
published: 2026-01-23T11:58:47.396Z
updated: 2026-01-23T11:59:05.483Z
tags: ["cyber", "windows", "phishing"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access

**[The Hacker News](https://daily.dev/sources/thn)** · 2 min read · 0 upvotes · 0 comments

## Summary

Cybersecurity researchers uncovered a sophisticated two-stage phishing campaign that steals email credentials through fake Greenvelope invitation notifications, then uses those credentials to register LogMeIn RMM accounts and deploy remote access tools. Attackers distribute a signed executable that silently installs LogMeIn Resolve, modifies Windows service settings for unrestricted access, and creates hidden scheduled tasks for persistence. This approach weaponizes legitimate IT administration tools to bypass security perimeters, making detection more difficult than traditional malware.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/phishing-attack-uses-stolen-credentials.html>

## Similar posts on daily.dev

- [RMM Tools Fuel Stealthy Phishing Campaign](https://daily.dev/posts/rmm-tools-fuel-stealthy-phishing-campaign-2snls3mpu) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#windows](https://daily.dev/tags/windows), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/phishing-attack-uses-stolen-credentials-to-install-logmein-rmm-for-persistent-access-oyzsvb4za)
