IN this SANS Internet Storm Center Stormcast, the host explains how attackers abuse legitimate remote administration tools to gain remote access without using malware. In one case, they email a copy of Screen Connect preconfigured to automatically connect back to the attacker when started. The attacker relies on users with limited technical knowledge who may grant remote access after opening the tool.
The message emphasises that control of remote admin tools is crucial, as many intrusions rely on tools that are legitimate, either installed by users or pre-existing on systems, rather than exclusively on malicious software.
The discussion also covers two other threats observed by researchers. First, Huntress reported abuse of OpenAI’s custom GPT feature to deliver phishing messages, steering users to click-fix pages that prompt users to paste strings into a terminal—exploiting the legitimacy of a customised ChatGPT experience. Second, SecConsult highlighted a vulnerability in email identity spoofing linked to SMTP header handling—specifically line termination manipulation that can mislead iCloud’s from-header attribution.
Apple reportedly patched this issue after disclosures dating back to 2024; a related, less clearly patched concern involves ProtonMail’s use of Unicode homographs to impersonate identities. The podcast notes these are subtle, harder to detect, and stresses ongoing vigilance around evolving legitimate tools and cloud-based identity systems.