THREAT actors are abusing a Remote Management and Monitoring (RMM) tool from Action1 in the wild, following a phishing email that delivers a fake PDF invoice. Opening the PDF triggers an OpenAction that redirects the user to a malicious VBS file, which then displays a decoy PDF and downloads an MSI package. The VBS is straightforward and un-obfuscated; the MSI (action1[.]msi) installs four files that are not flagged by VirusTotal and are signed with an “Action1 Corporation” certificate that expired in May 2026.
The files appear to be part of the Action1 RMM tool, with the dropper installing a persistence service named A1Agent (Action1 Agent) and creating a registry key at HKLM\Software\Action1\Agent containing CustomerId, Certificate, PrivateKey, MSI, and INSTALLDIR.
Evidence provided by the report includes specific SHA-256 sums for the downloaded components (a1_7z_dll_file, a1_sas_dll_file, action1_remote_exe, main_service_exe) and details of the installed path (C:\Windows\Action1\action1_agent.exe). The CustomerID is listed as 49b18106-681d-456a-b098-092e2818c09a, and the malware communicates with Action1 infrastructure via server.na-2.action1[.]com.
The author notes this pattern mirrors earlier abuse of ScreenConnect by threat actors, suggesting the cloud infrastructure of the vendor (potentially a free or test account) is being exploited to enable operation. Practical response steps are not prescribed in this diary, but organisations using Action1 should review for unauthorised A1Agent installations and monitor for the described registry keys and network endpoints. Published 6 October 2026.