Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

TrustConnect

159
Global rank
196 infographic chevron month
Month rank
192 infographic chevron week
Week rank
0
IOCs

TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.

RAT
Type
Unknown
Origin
20 January, 2026
First seen
19 June, 2026
Last seen

How to analyze TrustConnect with ANY.RUN

RAT
Type
Unknown
Origin
20 January, 2026
First seen
19 June, 2026
Last seen

IOCs

IP addresses
20.190.160.67
199.232.214.172
95.101.176.121
2.16.10.162
104.46.162.225
52.110.17.19
185.182.187.10
48.192.1.64
20.190.159.73
23.11.40.157
184.86.251.15
184.86.251.8
40.127.240.158
74.178.240.61
20.72.205.209
51.104.136.2
23.52.181.212
20.165.94.54
23.216.77.36
23.216.77.38
Hashes
2b4b2d4a06044ad0bd2ae3287cfcbecd90b959feb2f503ac258d7c0a235d6fe9
36fdd4693b6df8f2de7b36dff745a3f41324a6dacb78b4159040c5d15e11acb7
a593ff083096fd5f7d3ff3761f5ff3f972f649f2619cc763c216b5bc5371e949
492c5be14a97aadf50f444e8fc4c7be7e0cbd7120ac4f2ef7f9025e2bc277639
a1d4a97bb34efb036f6c5b49f656f999ba0e30865771cf3e946f106a93f5cf38
16a90595d3b7ab6ccf873d88ed160563846068e38fedbb8518fed41ceda1e234
5e9a7996fe94d7be10595d7133748760bf8348198b71b7a50fd8affaa980ac61
72e7b64196db3ee70e6408823fbf8af5d66b75140a582e9329a5442c2aa9e9de
02101b3f53f2d3b0f8c31e595e90e3d8801701ea009555423d3802d598560aad
31d6b3627939bb96db10a3c64cc01f33b71680f3c3dc2631a64b5d65ce4d5650
6b74dc7e0465d31f0b140ed3612f3a84625455ada38a3de2a64e9c2ad7f22b6d
af651ebcacd88d292eb2b6cbbe28b1e0afd1d418be862d9e34eacbd65337398c
12a6373a6ed9c103e67e480ed1ebc3963764efde0dc27178656dada71e632daa
d971461734e904a6009f77527e85e97f6e1d9bcb3bdf1dd5358ddd0bd4268b4c
d44cd2fc9f9eb1b4028c2400d0daccded1e741a6f8837f7ea298eaa93bee1fb0
b6927392e6084cd5f00ffffa769eea3b40884d8fa6373ad808c4c0fb61f4c1dc
a54336bff382ee75531ad7067b696654e3c7712795d4dfd4faece7a4c1400d2f
95a02e65784e47af71f3ac4b6804423013a20c2e24499d998c03105a5d966f1f
61542d98ed9bf73924caedf28d3b5b33c8458401e5b44d80fc967d2802633bea
f49b515eedeed1abe391bc32f15ce43d3582cb6c41ff944fa9c79f476d5824ba
Domains
ctldl.windowsupdate.com
google.com
login.live.com
self.events.data.microsoft.com
dns.msftncsi.com
officeclient.microsoft.com
fs.microsoft.com
trustconnectsoftware.com
www.microsoft.com
th.bing.com
fe3cr.delivery.mp.microsoft.com
nexusrules.officeapps.live.com
www.bing.com
settings-win.data.microsoft.com
ocsp.digicert.com
crl.microsoft.com
client.wns.windows.com
oneocsp.microsoft.com
activation-v2.sls.microsoft.com
slscr.update.microsoft.com
URLs
http://www.msftconnecttest.com/connecttest.txt
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8e6a0dbf544de4a5
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?923890bb1619c380
https://self.events.data.microsoft.com/onecollector/1.0/
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ec99790fc8df0165
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?3ecdd0df2b680329
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7873d7a9875e19fe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=4%2f16%2f2026%2c%209%3a33%3a17%20am
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2585
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7440
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10551
comments 0

(Don't) TrustConnect: The $300/Month RAT Dressed as Your IT Team's Best Friend

Key Takeaways

  1. TrustConnect is a professional MaaS RAT: its operators built a fake software company, obtained an EV certificate, and created a polished C2 dashboard. This level of investment signals a durable, scalable criminal enterprise, not a one-off campaign.

  2. EV certificates are not trust guarantees: TrustConnect demonstrated that Extended Validation certificates can be obtained through deception.

  3. Unlike passive infostealers, TrustConnect gives an operator complete interactive control of a victim machine — enabling banking fraud, data exfiltration, lateral movement, and sabotage in real time.

  4. Infrastructure takedowns are temporary: TrustConnect rebranded to DocConnect within hours of its C2 being taken offline. Detection strategies must target persistent behavioral patterns and TTPs, not just static IOCs tied to a specific campaign.

  5. By detonating TrustConnect samples in ANY.RUN's cloud-based Interactive Sandbox, analysts can observe real-time C2 registration, RDP stream initiation, follow-on ScreenConnect deployment, and PowerShell execution — generating rich behavioral IOCs that static analysis tools miss entirely.

View TrustConnect sample analysis

TrustConnect malware analysis in Interactive Sandbox TrustConnect fresh sample analysis in Interactive Sandbox

  1. Security teams can query ANY.RUN’s Threat Intelligence Lookup using TrustConnect indicators — IPs, hashes, process names, or command-line patterns — across 30+ parameters, with results in under five seconds and direct links to sandbox sessions showing the malware in action.
    threatName:"trustconnect".

TrustConnect sandbox analyses found in TI Lookup TrustConnect sandbox analyses found in TI Lookup

  1. The MaaS model is accelerating: Law enforcement actions against RedLine, Lumma, and Rhadamanthys have created market opportunities for new MaaS entrants. TrustConnect is one example of many — expect more sophisticated, AI-assisted, subscription-based threat platforms to emerge in 2026.

What is TrustConnect Malware?

TrustConnect is part of a growing trend where cybercriminals design malware to resemble legitimate enterprise software products.

Instead of simply distributing a malicious executable, the operators behind TrustConnect built:

  • A professional website posing as a software vendor;

  • Documentation and support pages;

  • A subscription portal used as the malware command-and-control interface;

  • A digitally signed application using an Extended Validation (EV) certificate obtained under a fake company identity.

The malware is presented as a remote administration tool called TrustConnectAgent, which victims install believing it to be legitimate software. After installation, the malware establishes persistent communication with a centralized command portal where attackers manage infected systems.

Unlike many RATs, TrustConnect integrates features typical of enterprise RMM solutions, including remote desktop access, file transfers, and centralized device management.

The domain trustconnectsoftware[.]com was registered on January 12, 2026. Within days, the operator had:

  • Launched an AI-generated website presenting "TrustConnect Software PTY LTD" (nominally based in Alexandra, South Africa) as a legitimate SaaS provider;

  • Purchased an Extended Validation (EV) code-signing certificate under that fictitious company identity — EV certificates involve enhanced identity checks and cost thousands of dollars, giving malicious files the appearance of being trusted software;

  • Built a C2 backend (hosted at 178[.]128[.]69[.]245) serving both as a criminal subscription portal and as the actual malware command infrastructure;

  • Begun distributing malicious executables to victims by January 26–27, 2026.

The EV certificate was revoked on February 6, 2026, through a coordinated effort by Proofpoint and certificate-intelligence specialists at The Cert Graveyard. However, because certificate revocation is not retroactive, all signed samples distributed before that date remained valid. Proofpoint and anonymous industry partners took down the primary C2 infrastructure around February 17, 2026. Within hours, the operator had already pivoted to parallel infrastructure and began testing a rebranded variant called DocConnect (also dubbed "SHIELD OS v1.0"), this time using a React Single Page Application (SPA) backed by Supabase — demonstrating exceptional operational resilience.

Proofpoint assessed with moderate confidence that both the TrustConnect and DocConnect websites and agent codebases were developed with the assistance of AI tooling — a trend that is dramatically lowering the barrier to building convincing MaaS infrastructure.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How TrustConnect Threatens Businesses and Organizations

TrustConnect poses a multi-dimensional threat to enterprises, specifically because it exploits the intersection of trusted software appearance, legitimate network protocols, and low operator technical skill requirements.

1. Full Remote Takeover

Once installed, TrustConnect gives the subscribing criminal complete keyboard-and-mouse control over the victim's workstation, including the ability to hide their own activity from the victim's screen. This goes far beyond passive data theft: an operator can actively conduct banking fraud, transfer files, install additional payloads, modify configurations, or pivot to other systems on the same network.

2. Trusted Software Masquerading

Because TrustConnect executables are signed with an EV certificate and visually mimic Zoom, Microsoft Teams, Adobe Reader, or Google Meet, complete with matching icons, file names, and metadata, they are highly likely to bypass standard user suspicion and first-generation signature-based antivirus scanning. Employees who routinely install IT tools or respond to IT helpdesk tickets are natural targets.

3. Multi-Layer Persistence

Proofpoint observed TrustConnect being used to deploy follow-on payloads — specifically, self-hosted instances of ScreenConnect from at least nine distinct servers (many running legacy versions with expired or revoked certificates). This creates a layered persistence mechanism: even if the initial TrustConnect agent is detected and removed, legitimate-looking RMM software remains on the system.

4. Resilient Infrastructure

The operator's ability to rebuild infrastructure within hours of takedown — and pivot to a rebranded DocConnect variant — means that enterprise defenders cannot rely on perimeter blocks of known IOCs alone. The threat is structurally resilient by design.

Victimology: Which Industries Are Most at Risk?

TrustConnect's attack surface is deliberately broad. The MaaS platform provides lure templates covering taxes, document sharing, bid invitations, meeting requests, government communications, and branded corporate software — meaning virtually any professional sector is a viable target. However, certain industries carry elevated structural risk:

Is your business threatened by TrustConnect? Is your business threatened by TrustConnect?

The healthcare, financial services, and government sectors are particularly attractive because they combine high-value data, mission-critical uptime requirements (creating ransomware leverage), and workforces accustomed to receiving documents and remote-support requests via email. MSSPs and IT service providers are especially high-value targets because compromising a single MSP can yield access to dozens of downstream client environments.

How Can Businesses Proactively Protect Against TrustConnect

Reactive defenses are insufficient against an adversary that rebuilds infrastructure within hours and rebrands payloads overnight. Proactive threat intelligence is essential. ANY.RUN's Threat Intelligence Lookup and TI Feeds provide the contextual, continuously refreshed data organizations need to stay ahead of TrustConnect and its successors.

For TrustConnect specifically, TI Lookup enables defenders to:

  1. Search for TrustConnect's known C2 IP and associated domains to identify whether any internal hosts have communicated with the infrastructure:

destinationIP:"178.128.69.245".

TrustConnect samples using the IP connection TrustConnect samples using the IP connection

  1. Query file hashes of known TrustConnect installers (MsTeams.exe, AdobeReader-XX.exe, etc.) to determine whether any have been seen in the environment.

  2. Track the evolution of TrustConnect TTPs — including the pivot to DocConnect — before those indicators surface in other intelligence sources.

  3. Search by behavioral artifacts such as the TrustConnectAgent.exe process name, PowerShell command-line patterns, or WebSocket-based screen streaming behavior.

filePath:"TrustConnectAgent.exe".

TrustConnect process in sandbox detonations TrustConnect process in sandbox detonations

  1. Cross-reference TrustConnect indicators with historical Redline stealer data to understand the operator's broader toolset and targeting.

ANY.RUN's TI Feeds deliver continuously updated IOC streams — malicious IPs, URLs, domains — in STIX/TAXII format, directly compatible with SIEMs, TIPs, firewalls, IDS/IPS, and EDR platforms. Data is refreshed every two hours, drawn from the same sandbox analysis community and enriched with associated event fields (not just bare indicators) for full operational context. For TrustConnect:

  • Block known TrustConnect and DocConnect C2 infrastructure automatically in SIEM/firewall rules before an incident occurs.

  • Receive immediate IOC updates as the operator pivots to new hosting or generates new payload variants.

  • Use the associated event context — not just IP addresses, but the processes, file paths, and network behaviors tied to each IOC — to write precise detection rules.

  • Integrate TrustConnect-related indicators into EDR policies to flag execution of renamed or impersonated installer binaries.

Additional Protective Measures

Beyond ANY.RUN's intelligence products, organizations should implement the following defensive controls:

  • Email security hardening: Deploy advanced email gateway filtering with sandboxed attachment/URL detonation, covering tax, bid, DocuSign, meeting, and government-themed lures.

  • Application allowlisting: Prevent execution of unsigned or unknown executables in standard user environments; enforce signed binary policies aligned with known good publishers.

  • PowerShell restrictions: Implement Constrained Language Mode and script-block logging; alert on PowerShell one-liners consistent with ClickFix deployment patterns.

  • RMM governance: Maintain a formal inventory of authorized RMM tools; immediately investigate any RMM process not on the approved list.

  • EV certificate vigilance: Train security teams to understand that EV certificates do not equal trustworthiness — they can be fraudulently obtained.

  • User awareness training: Run simulated phishing campaigns using the exact lure types TrustConnect employs: meeting invites, bid requests, tax notices, DocuSign.

  • Network monitoring: Alert on outbound WebSocket connections to unexpected hosts; monitor for anomalous screen-sharing or RDP-over-browser traffic patterns.

  • Incident response planning: Ensure IR playbooks explicitly address MaaS RAT scenarios with follow-on RMM persistence.

    Integrate ANY.RUN’s threat intelligence solutions in your company

    Contact us

Sandbox Analysis of TrustConnect Sample

See full execution chain of TrustConnect

ANY.RUN sandbox revealing TrustConnect behavior in real time ANY.RUN sandbox revealing TrustConnect behavior in real time

The file is downloaded under the name msteams and is signed by TrustConnect Software PTY LTD.

TrustConnect initial file TrustConnect initial file

The configuration file config.json left by the sample reveals the main operational parameters of the malware. The ApiServer field specifies the C2 server address. The InstallToken and OrganizationId parameters are unique identifiers that link a specific victim to a particular operator in the TrustConnect management panel. The BrandName and ServiceName settings serve as obfuscation parameters.

TrustConnect configuration file TrustConnect configuration file

Next, the malware proceeds to follow this configuration. It copies itself to the folder C:\Program Files\Microsoft Teams\MsTeams.exe. It then registers itself in the Windows registry as an installed program: keys appear in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Teams with the publisher listed as TrustConnect Software Ltd, allowing the malware to appear in the list of installed programs as a legitimate application.

At the same time, a Windows service named Microsoft Teams is created with the description “Microsoft Teams – Remote Support Agent.” This service adds the executable to system startup. Event sources TrustConnectAgent and MsTeams are also created in the Windows Application event log.

TrustConnect’s registry changes TrustConnect’s registry changes

Additionally, a large number of connections were observed to 185[.]182[.]187[.]10, which resolves from the domain trustconnectsoftware.com.

Conclusion

TrustConnect demonstrates how cybercriminals are increasingly adopting enterprise-grade tactics to make malware appear legitimate.

By building a fake software company, purchasing a trusted digital certificate, and selling access through a subscription portal, the operators behind TrustConnect blurred the line between legitimate enterprise software and malware.

For organizations, this case highlights a key lesson: trust signals such as digital signatures or professional websites are no longer reliable indicators of safety.

Proactive threat intelligence, behavioral analysis, and strong detection workflows are essential to identifying and stopping threats like TrustConnect before they escalate into full-scale breaches.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
VanHelsing Ransomware screenshot
VanHelsing is a sophisticated ransomware strain that appeared in early 2025, operating via the Ransomware-as-a-Service (RaaS) model and targeting primarily USA and France. It threatens mostly Windows systems but has variants for Linux, BSD, ARM, and ESXi, making it a multi-platform malware. It is also notable for its advanced evasion techniques, double extortion tactics, and rapid evolution.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
PXA Stealer screenshot
PXA Stealer
pxastealer
PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.
Read More