New Attack Campaign Weaponizes Trusted Datto RMM, Leaving Businesses Blind to Full Remote Takeover

Fortra Intelligence and Research Experts (FIRE) are tracking a previously unseen threat campaign abusing Datto’s legitimate RMM platform as a stealthy command‑and‑control channel. By routing attacker traffic through the legitimate Datto infrastructure, threat actors gain full, persistent remote access to victim systems while evading standard network and endpoint defenses.

For businesses, the impact could be severe: undetected access enables data theft, lateral movement, and ransomware staging, all masked as normal IT activity. The campaign is actively maintained, uses weekly‑recompiled malware, and underscores a growing risk – attackers weaponizing trusted enterprise tools to make compromise effectively invisible.

You can read the details here: https://www.fortra.com/blog/fortra-discovers-datto-living-land-binary

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading