Signed malware impersonating workplace apps deploys RMM backdoors

2026-03-04T21:20:03Z24f74309eb79f2e30bc25500572cfe923e86c4a75e6ff0bf4f0594e775ac1f81
agent-securityai-securitybackdoorcode-signingcommand-and-controlcopilot-studiodeveloper-targetingmalware-deliverymicrosoft-defendermisconfigurationnext.jsnpmoauth-redirectionopenclawpersistencephishingrcermmruntime-isolationsecurity-operationssigned-malwaresoc-opsstolen-ev-certificatesupply-chainthreat-modeling

What happened

Microsoft Security Blog posts (Feb–Mar 2026) describe multiple active and emerging enterprise threats and defensive guidance: signed malware using a stolen EV certificate that impersonates workplace apps to deploy legitimate RMM tools and establish persistent backdoors; OAuth redirection abuse used to convert trusted auth flows into phishing and malware delivery vectors; developer-targeting supply‑chain attacks using malicious Next.js repositories to trigger covert RCE→C2 chains during standard build workflows. Additional posts cover AI threat‑modeling, risks from self‑hosted agents (OpenClaw‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
24f74309eb79f2e30bc25500572cfe923e86c4a75e6ff0bf4f0594e775ac1f81
Enrichment time
2026-03-04T21:20:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.