Threat actors continue to abuse legitimate remote monitoring and management (RMM) tools in phishing campaigns to bypass traditional anti-virus detection and gain unauthorized remote access to systems. The NJCCIC observed a growing trend of threat actors abusing the FleetDeck RMM tool by impersonating major brands in finance, payment, or logistics-themed phishing emails.
In one campaign, messages purport to be from Walgreens with a subject line referencing that their prescription is ready for pickup. The phishing email includes either an Adobe PDF file named “medication.pdf” or a compressed file named “medication.pdf.uue.” The attachment contains a link that, if clicked, downloads the FleetDeck Agent. Once installed, threat actors use it for persistence, reconnaissance, credential harvesting, data exfiltration, and the deployment of additional malware, such as ransomware.

In another campaign, threat actors impersonate Chase Bank and lure users with secure document notifications. Messages purport to be account statements that are ready for review. If the link is clicked, users are directed to an HTML file hosted through GitHub’s user-attachments infrastructure. If users open and click the executable, the FleetDeck Agent is installed.
Recommendations
- Exercise caution with unexpected or unsolicited communications.
- Confirm requests from senders using contact information obtained from verified, official sources before taking any action, such as clicking links or opening attachments.
- Keep systems and browsers up to date and apply patches after appropriate testing.
- Maintain robust and up-to-date endpoint detection tools on every endpoint.
- Consider leveraging behavior-based detection tools rather than signature-based tools.
- Utilize network segmentation to isolate valuable assets and help prevent the spread of ransomware and malware.
- Enforce the Principle of Least Privilege, disable unused ports and services, and use web application firewalls (WAFs).
- Establish a comprehensive data backup plan that includes regularly performing scheduled backups, keeping an updated copy offline in a separate and secure location, and testing it regularly.

