It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.
Same scenario, it started with a phishing email that delivers a fake PDF invoice to the victim:

When the PDF is opened, it just redirect to a malicious VBS file. Indeed, the PDF contains an “OpenAction” and “URI” keywords, that sounds weird!
remnux@remnux:~/files/samples$ pdf-parser.py Transaction\ Receipt\ .pdf -o 3
obj 3 0
Type: /Page
Referencing: 1 0 R, 2 0 R, 4 0 R
<<
/Type /Page
/Parent 1 0 R
/Resources 2 0 R
/MediaBox [0 0 595.2799999999999727 841.8899999999999864]
/Annots
<<
/Type /Annot
/Subtype /Link
/Rect [0. 841.8899999999999864 595.2799999999999727 71.3010032362460606]
/Border [0 0 0]
/A
<<
/S /URI
/URI (hxxps://up-theta-rose.vercel[.]app/adobe_new_update.vbs)
>>
>>
] /Contents 4 0 R
>>
The URL will be visited thanks to the OpenAction. This is a common trick to avoid writing URLs in email bodies that can be easily detected.
The VBS file is pretty simple and even not obfuscated. It will display another PDF as a decoy: a non-blurred version of the initial attachment.
In parallel, a MSI archive will be downloaded and installed:
hxxps://up-theta-rose.vercel[.]app/action1.msi
The MSI file contains 4 files that are not reported as malicious by VT:
$ sha256sum * eaff35d250c9b04f51c971e70082740dbfeee5dd846829d541f588ad43378727 a1_7z_dll_file 996b01e15f85e165899630721a141b178a9c372b6e878012180ec9e9d4e7bd06 a1_sas_dll_file 1b19115d5ebdc216e0ab3adf2c643648cfc70a385f4caf0217c679f9f3b20342 action1_remote_exe 941695d20d82dd5d62f74b0111feb23720637202f6c797df2a02e2cb6cb6e8e3 main_service_exe
These files belongs to the RMM tool developed by Action1[2] and are signed with an "Action1 Corporation" certificate that expired in May 2026.
The tool installs itself as a service for persistence ("A1Agent" - "Action1 Agent"), executing C:\Windows\Action1\action1_agent.exe.
The registy key "HKLM\Software\Action1\Agent" contains the values: CustomerId, Certificate, PrivateKey, MSI & INSTALLDIR.
The CustomerID is: 49b18106-681d-456a-b098-092e2818c09a and is connecting to the Action1 infrastructure via server[.]na-2.action1[.]com.
We are facing here the same behaviour: the threat actor abuse the cloud infrastructure of the company developing the RMM tool, probably using a free/test account.
[1] https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388
[2] https://www.action1.com/remote-access/
Xavier Mertens (@xme)
Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
Xameco | PGP Key