SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Phishing campaign plants Action1 remote-management agent through fake PDF invoices
Phishing emails carrying fake PDF invoices are installing Action1's remote-management agent, SANS ISC handler Xavier Mertens reported. It follows a ScreenConnect campaign he documented a few days earlier that used the same fake-invoice lure.
The Watch · Security desk

PDF readers: OpenAction visits a VBS URL on open. VirusTotal: the MSI's four files not reported malicious. Action1 cloud: abused, probably via a free/test account. Vercel: both samples staged payloads there. Windows hosts: agent persists as the A1Agent service.
- exposure PDF readers A link annotation covers the page, and the OpenAction visits the VBS URL when the PDF is opened, claim 2
- constraint VirusTotal scans The MSI's four files are not reported as malicious by VirusTotal, claim 6
- exposure Action1 cloud The threat actor abuses the RMM vendor's cloud infrastructure, probably using a free/test account, claim 11
- exposure Vercel hosting Both samples staged their payloads on vercel.app subdomains, claim 13
- exposure Victim Windows hosts The tool installs itself as the A1Agent service for persistence, claim 8
| Who | How | Kind | Claim |
|---|---|---|---|
| PDF readers | A link annotation covers the page, and the OpenAction visits the VBS URL when the PDF is opened | exposure | 2 |
| VirusTotal scans | The MSI's four files are not reported as malicious by VirusTotal | constraint | 6 |
| Action1 cloud | The threat actor abuses the RMM vendor's cloud infrastructure, probably using a free/test account | exposure | 11 |
| Vercel hosting | Both samples staged their payloads on vercel.app subdomains | exposure | 13 |
| Victim Windows hosts | The tool installs itself as the A1Agent service for persistence | exposure | 8 |
What happened
- Opening the PDF fires an OpenAction that sends the reader straight to a VBS file hosted at up-theta-rose.vercel[.]app.
- The unobfuscated script shows an unblurred copy of the invoice as a decoy while it downloads and installs action1.msi.
- The installed agent carries CustomerId 49b18106-681d-456a-b098-092e2818c09a and connects to Action1's cloud at server[.]na-2.action1[.]com.
- A second sample posing as a DHL document used an HTA script inside a ZIP archive and delivered the same MSI.
Why it matters
- constraint Hash and reputation checks cannot separate this agent from a sanctioned Action1 install; the difference is whether anyone approved the deployment and whose CustomerId it carries.
- exposure Organisations that already allow Action1 traffic for their own IT team have left the same outbound path open to this agent, with only the tenant behind it different.
- precedent With two RMM brands behind one lure in a few days, a list of known-abused tools will trail the next swap, while an allowlist of approved RMM software already covers it.
The link is inside the PDF. Mertens, a senior handler at the SANS Internet Storm Center, found "OpenAction" and "URI" keywords in the attachment, with a page-sized link annotation behind them [1][2]. "This is a common trick to avoid writing URLs in email bodies that can be easily detected," he wrote [3]. We'd expect mail filters that score URLs in the message body to let these emails through.
The payload makes no attempt to evade antivirus. The MSI holds four files, among them action1_remote_exe and main_service_exe, and VirusTotal reported none of them as malicious [6]. They are Action1's own binaries, signed with an "Action1 Corporation" certificate that expired in May 2026 [7]. The agent persists as a service named A1Agent that runs `C:\Windows\Action1\action1_agent.exe` [8]. Its configuration sits under `HKLM\Software\Action1\Agent`, in values named CustomerId, Certificate, PrivateKey, MSI and INSTALLDIR [9].
"We are facing here the same behaviour: the threat actor abuse the cloud infrastructure of the company developing the RMM tool, probably using a free/test account," Mertens wrote [11]. The trial account is his assessment, and he hedges it with "probably" [11].
We think this is cheap to stop at an organisation that does not use Action1. There, an A1Agent service, a `C:\Windows\Action1` directory or a connection to server[.]na-2.action1[.]com counts as a finding with no other evidence needed [8][10]. Both payload hosts in the diary were vercel.app subdomains [13].
Mertens opened the diary with "It seems that a trend started" [15]. In our view the operator can swap the script wrapper and the RMM brand freely, since the HTA variant still ended at the identical MSI [12]. The diary does not name an actor or say whether the VBS runs without a further click from the victim.
What to watch
- Action1 action against the account behind CustomerId 49b18106-681d-456a-b098-092e2818c09a, or new limits on free and trial tenants.
- A third RMM product appearing behind the same fake-invoice PDF and vercel.app staging.
- Any report tying the ScreenConnect and Action1 waves to one operator, or giving victim counts.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence72
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Xavier Mertens, Senior ISC Handler at SANS, reported a phishing campaign in which an email delivers a fake PDF invoice that leads to installation of the Action1 RMM agent.
- [2]
The PDF contains OpenAction and URI keywords; a link annotation covering the page points to hxxps://up-theta-rose.vercel[.]app/adobe_new_update.vbs, and the URL is visited thanks to the OpenAction when the PDF is opened.
- [3]
"This is a common trick to avoid writing URLs in email bodies that can be easily detected."
- [4]
The VBS file is simple and not obfuscated; it displays another PDF as a decoy, a non-blurred version of the initial attachment.
- [5]
The unobfuscated VBS displays a non-blurred decoy copy of the attachment and, in parallel, downloads and installs an MSI from hxxps://up-theta-rose.vercel[.]app/action1.msi.
- [6]
The MSI contains four files (a1_7z_dll_file, a1_sas_dll_file, action1_remote_exe, main_service_exe) that are not reported as malicious by VirusTotal.
- [7]
The files belong to the RMM tool developed by Action1 and are signed with an "Action1 Corporation" certificate that expired in May 2026.
- [8]
The tool installs itself as a service for persistence ("A1Agent" - "Action1 Agent"), executing C:\Windows\Action1\action1_agent.exe.
- [9]
The registry key HKLM\Software\Action1\Agent contains the values CustomerId, Certificate, PrivateKey, MSI and INSTALLDIR.
- [10]
The CustomerID is 49b18106-681d-456a-b098-092e2818c09a and the agent connects to the Action1 infrastructure via server[.]na-2.action1[.]com.
- [11]
"We are facing here the same behaviour: the threat actor abuse the cloud infrastructure of the company developing the RMM tool, probably using a free/test account."
- [12]
In an update at 15:11 CET, a second sample mimicking a DHL document carried a URL (hxxps://update-two-tau[.]vercel[.]app/adobe-ne) pointing to a ZIP archive with an HTA script, which delivers the same MSI file.
- [13]
Both samples in the diary staged their payloads on vercel.app subdomains: up-theta-rose.vercel.app and update-two-tau.vercel.app.
- [14]
A few days earlier, Mertens wrote a diary about ScreenConnect being abused in the wild; the Action1 case follows the same scenario, starting with a phishing email delivering a fake PDF invoice.
ReportedInsufficientSource: Xavier Mertens, SANS ISC2 sources— create a free account to open themView cited source - [15]
"It seems that a trend started"
ReportedInsufficientSource: Xavier Mertens, SANS ISC2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- https://isc.sans.edu/diary/33400
isc.sans.edu
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Legitimate RMM AbuseFollow
- Malicious PDF documentsFollow
- PhishingFollow