VORANT. Threat Intelligence Research Sign in Create a free account

Phishing abuses Action1 RMM for persistence

routine threat

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Phishing emails deliver fake PDF invoices that redirect to a VBS downloader installing the legitimate Action1 RMM tool for persistent remote access.

SANS ISC researcher Xavier Mertens documented a phishing campaign abusing the Action1 Remote Monitoring and Management (RMM) tool, continuing a trend of attackers leveraging legitimate RMM software to gain persistent access to victim machines. The attack begins with a phishing email containing a fake PDF invoice. The PDF uses an OpenAction/URI trick to automatically redirect the victim's browser to a malicious VBS file hosted on a Vercel app subdomain, bypassing email URL detection since no URL appears in the email body itself.

The unobfuscated VBS script displays a decoy (non-blurred) version of the original PDF while silently downloading and installing an MSI package containing legitimate Action1 RMM binaries, signed with a valid (though expiring 2026) Action1 Corporation certificate. The tool installs as a persistent Windows service (A1Agent) running from C:\Windows\Action1\action1_agent.exe, storing configuration including CustomerId, Certificate, and PrivateKey in the registry under HKLM\Software\Action1\Agent, and communicates with Action1's legitimate cloud infrastructure (server.na-2.action1.com) - likely via a free or trial account created by the threat actor.

This mirrors a similar technique the author previously reported using ScreenConnect, indicating attackers are increasingly abusing commercial RMM platforms' legitimate, signed binaries and cloud infrastructure to evade detection and establish remote access without deploying custom malware. Defenders should monitor for unexpected installation of RMM tools (especially Action1) that were not deployed by IT, check for the specific CustomerId indicator, and treat any unsanctioned RMM agent installation as a potential compromise.

Mentioned in this report

Malware Action1

Detection guidance

Action1 RMM Agent Service Installed

ATT&CK T1543.003

Detects installation of the Action1 agent as a Windows service (A1Agent) running from the Action1 directory, as used for persistent RMM access after a phishing VBS drops an MSI. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Action1 RMM Agent Service Installed
description: Detects a Windows service install event for the Action1 agent (A1Agent
  / action1_agent.exe). Unsanctioned installs on hosts not managed by Action1 by IT
  indicate RMM abuse for persistence.
tags:
- attack.persistence
- attack.t1543.003
- attack.t1219
logsource:
  product: windows
  service: system
detection:
  selection:
    EventID: 7045
  selection_action1:
  - ServiceName: A1Agent
  - ImagePath|contains: \Action1\action1_agent.exe
  condition: selection and selection_action1
falsepositives:
- Legitimate IT deployment of Action1 across managed endpoints
- MSP onboarding of a new customer endpoint
level: medium
id: 5bc8d3e0-928c-5380-b654-31697a4918e4
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33400

Script Host Spawning Msiexec for Silent Package Install

ATT&CK T1059.005

Detects wscript/cscript running a VBS that launches msiexec for a quiet install, matching the VBS-dropped Action1 MSI chain. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Script Host Spawning Msiexec for Silent Package Install
description: Detects wscript.exe or cscript.exe spawning msiexec.exe with quiet or
  remote-URL install flags. This matches a phishing-delivered VBS silently installing
  an RMM MSI such as Action1 or ScreenConnect.
tags:
- attack.execution
- attack.t1059.005
- attack.t1204.002
- attack.t1219
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
    - \wscript.exe
    - \cscript.exe
  selection_child:
    Image|endswith: \msiexec.exe
  selection_flags:
    CommandLine|contains:
    - /i
    - -i
    - /package
  selection_quiet:
    CommandLine|contains:
    - /qn
    - /quiet
    - /passive
    - -qn
    - http
  condition: selection_parent and selection_child and selection_flags and selection_quiet
falsepositives:
- Legacy VBS-based software deployment or logon scripts installing MSI packages silently
level: high
id: 2531669c-d346-5608-9bbf-8cb3cfbd5c18
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33400

Action1 Agent Execution From Windows Directory

ATT&CK T1219

Detects execution of action1_agent.exe or Action1 MSI installer activity, indicating an Action1 RMM agent running on the host. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Action1 Agent Execution From Windows Directory
description: Detects process creation of the Action1 agent from C:\Windows\Action1
  or its client binary. Alert when the host is not an Action1-managed endpoint, as
  attackers use trial accounts for remote access.
tags:
- attack.command-and-control
- attack.t1219
- attack.t1036.005
logsource:
  category: process_creation
  product: windows
detection:
  selection_agent:
    Image|endswith:
    - \Action1\action1_agent.exe
    - \Action1\action1_remote.exe
  selection_parent_msi:
    ParentImage|endswith: \msiexec.exe
    CommandLine|contains: action1
  condition: 1 of selection_*
falsepositives:
- Organisations that legitimately use Action1 for endpoint management
- Authorised helpdesk remote sessions
level: medium
id: 3d573b41-7df4-5025-8391-f8bba7823848
status: experimental
author: Vorant
references:
- https://isc.sans.edu/diary/rss/33400

3 more detections for this report are in the app — the rules that match its indicators, plus every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. Three days of it free, no card.

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://isc.sans.edu/diary/rss/33400

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,812 reports from 152 sources, 462 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs