Signed malware impersonating workplace apps deploys RMM backdoors
2026-03-04T21:20:49Z•31c22a7f91fcf6ec35bbc03f125f5eb86adab48f6952f2593c84b5d5840f37b1
OpenClawagent-misconfigurationai-securitybackdoorc2ci-cd-securitycode-signingcommand-and-controldeveloper-supply-chainev-certificate-theftmalware-deliverynext.jsoauth-redirectionphishingrceremote-managementrmmsecurity-exposure-managementsecurity-operationsself-hosted-agentssigned-malwaresocthreat-modeling
What happened
Microsoft Security Blog posts highlight multiple high-risk trends: signed malware using a stolen EV certificate to impersonate workplace apps and deploy legitimate RMM tools as persistent backdoors; OAuth redirection abuse as a trusted-phish/malware delivery vector; developer-targeting campaigns delivering staged RCE→C2 via malicious Next.js repositories; and growing risks from self-hosted agents (OpenClaw-like) and common agent misconfigurations. Guidance across the posts emphasizes hardening certificate controls and code-signing, monitoring RMM and OAuth redirection telemetry, securing CI/CD
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 31c22a7f91fcf6ec35bbc03f125f5eb86adab48f6952f2593c84b5d5840f37b1
- Enrichment time
- 2026-03-04T21:20:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.