Hackers abusing ManageEngine UEM for unauthorized remote endpoint access

Hackers Are Abusing Legitimate UEM/RMM Tools
We are seeing an important attack pattern that enterprises, banks and IT teams should watch closely. Attackers are attempting to abuse ManageEngine UEM (Unified Endpoint Management) as a legitimate remote-management channel.

The attack flow can look like this:
A malicious script is executed on the endpoint or User receives ZIP with a signed EXE and a sideloaded DLL.
 The script / DLL downloads the ManageEngine .MSI installer
 The management/remote-control component gets installed silently
 The attacker then attempts to remotely manage or control the PC — without the user's informed consent

This is an important reminder:
The threat is not always malware. Sometimes attackers weaponize legitimate enterprise software.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

Traditional antivirus detection alone may not be enough when the binary being installed is digitally signed and belongs to a legitimate software vendor.
Organizations should therefore monitor:

 PowerShell / CMD / script-based MSI downloads
 msiexec.exe installations from unusual URLs or temporary folders
 Unexpected installation of UEM, RMM or remote-access agents
 Newly created services and scheduled tasks
 Outbound connections to unknown management servers
 Unauthorized enrollment of endpoints into external UEM consoles
 Application-control policies for remote-management software

For BFSI, Government and Enterprise environments, UEM/RMM tools should ideally be explicitly approved, centrally controlled and continuously monitored.
Zero Trust should apply not only to users and devices — but also to legitimate applications being used in an illegitimate manner.

At Net Protector Enterprise Cybersecurity, we are continuously studying such attack techniques to strengthen our EDR, Application Control and Endpoint Threat Detection capabilities. We are protecting the corporate network and systems from such attacks

 

Stay Ahead of Legitimate Tool Abuse with NPAV Endpoint Detection and Response (EDR)