Phishing now hijacks RMM tools and AI email assistants

icon

Phishing has always been about exploiting trust. Two new reports from Fortra and Barracuda show the attack surface expanding in two directions at once: toward the remote management tools your IT team already relies on, and toward the AI assistants now sitting in employee inboxes.

RMM Tools as Persistent Backdoors

Fortra reported a 475 percent increase in phishing attacks incorporating remote monitoring and management software during the first nine months of 2026 compared to all of 2025. The campaigns focused on North American financial institutions, with commercial banking accounts as the primary target.

The attack pattern starts with a phone call, email, or text warning the victim about a serious bank account problem. The victim lands on a counterfeit banking site with a fake customer support chat. That chat can trigger a download of a remote access app, most commonly AnyDesk. The attacker then walks the victim through installation and collects the connection key needed to take over the machine.

laptop showing video call near houseplant

From there, the attacker can watch everything on the device in real time. Fortra noted the downstream risks: credential and data theft, ransomware installation, using the compromised machine in other campaigns, or selling access through criminal marketplaces.

The detection problem is real. Security tools often recognize AnyDesk as a legitimate administration application and do not flag the session as unauthorized. Fortra’s first observation of these campaigns targeting U.S. financial institutions was in the third quarter of 2025. Activity peaked in Q1 2026, when attackers used standardized fake banking support pages and Firebase-hosted links to deliver AnyDesk. AnyDesk subsequently restricted direct downloads from Firebase domains after being notified. Fortra reports that reduced new attacks, but operators adapted by hosting executables elsewhere and hiding redirects inside embedded webpage elements.

Fortra’s recommended countermeasures: maintain an allowlist for approved RMM tools, block unauthorized installations, and train customers to recognize fake support interactions.

Prompt Injection Hidden Inside Emails

Barracuda’s report covers a separate but equally uncomfortable attack vector. A single email can carry a phishing lure for the human reader alongside hidden instructions targeting the AI assistant summarizing the message.

Those instructions can tell the assistant to label the email as legitimate or urgent, nudging the employee toward engaging with it. Barracuda found attackers hiding these instructions in invisible text and in the underlying HTML of the message. In one documented example, an invoice email contained a hidden instruction telling the AI assistant to add an urgent request to change a vendor’s payment details to its summary.

closeup of mail app icon on phone

“Protecting the inbox is no longer enough.” — Guruprasad Kenja, Barracuda threat analyst

Barracuda’s recommended defenses: strip hidden content before AI processing, implement prompt injection detection, limit what permissions the assistant holds, validate its outputs, and require human approval before the assistant takes any sensitive action. The core principle is that external messages should be treated as data to analyze, not instructions to follow.

The Operator Takeaway

If you run a small team or a solo operation that uses any AI inbox tooling, both reports are worth reading in full. The RMM threat is a reminder that legitimate software is as dangerous as malware when an attacker controls the session. The prompt injection threat is a reminder that AI assistants inherit the attack surface of everything they read.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo