Cybersecurity Alert: ManageEngine UEM from Zoho being used by Hackers.
Hackers Are Abusing Legitimate UEM/RMM Tools
We are seeing an important attack pattern that enterprises, banks and IT teams should watch closely. Attackers are attempting to abuse ManageEngine UEM (Unified Endpoint Management) as a legitimate remote-management channel.
The attack flow can look like this:
A malicious script is executed on the endpoint or User receives ZIP with a signed EXE and a sideloaded DLL.
The script / DLL downloads the ManageEngine .MSI installer
The management/remote-control component gets installed silently
The attacker then attempts to remotely manage or control the PC — without the user's informed consent
This is an important reminder:
The threat is not always malware. Sometimes attackers weaponize legitimate enterprise software.


Traditional antivirus detection alone may not be enough when the binary being installed is digitally signed and belongs to a legitimate software vendor.
Organizations should therefore monitor:
PowerShell / CMD / script-based MSI downloads
msiexec.exe installations from unusual URLs or temporary folders
Unexpected installation of UEM, RMM or remote-access agents
Newly created services and scheduled tasks
Outbound connections to unknown management servers
Unauthorized enrollment of endpoints into external UEM consoles
Application-control policies for remote-management software
For BFSI, Government and Enterprise environments, UEM/RMM tools should ideally be explicitly approved, centrally controlled and continuously monitored.
Zero Trust should apply not only to users and devices — but also to legitimate applications being used in an illegitimate manner.
At Net Protector Enterprise Cybersecurity, we are continuously studying such attack techniques to strengthen our EDR, Application Control and Endpoint Threat Detection capabilities. We are protecting the corporate network and systems from such attacks
Stay Ahead of Legitimate Tool Abuse with NPAV Endpoint Detection and Response (EDR)