Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Phishing campaign plants Action1 remote-management agent through fake PDF invoices

Phishing emails carrying fake PDF invoices are installing Action1's remote-management agent, SANS ISC handler Xavier Mertens reported. It follows a ScreenConnect campaign he documented a few days earlier that used the same fake-invoice lure.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Phishing campaign plants Action1 remote-management agent through fake PDF invoices
Photo: isc.sans.edu
Attacker abuses Action1's cloud infrastructure How the fake-invoice Action1 campaign reaches each scanner, platform and host, per Xavier Mertens's SANS ISC diary.

PDF readers: OpenAction visits a VBS URL on open. VirusTotal: the MSI's four files not reported malicious. Action1 cloud: abused, probably via a free/test account. Vercel: both samples staged payloads there. Windows hosts: agent persists as the A1Agent service.

Attacker abuses Action1's cloud infrastructure
WhoHowKindClaim
PDF readersA link annotation covers the page, and the OpenAction visits the VBS URL when the PDF is openedexposure2
VirusTotal scansThe MSI's four files are not reported as malicious by VirusTotalconstraint6
Action1 cloudThe threat actor abuses the RMM vendor's cloud infrastructure, probably using a free/test accountexposure11
Vercel hostingBoth samples staged their payloads on vercel.app subdomainsexposure13
Victim Windows hostsThe tool installs itself as the A1Agent service for persistenceexposure8

What happened

  • Opening the PDF fires an OpenAction that sends the reader straight to a VBS file hosted at up-theta-rose.vercel[.]app.
  • The unobfuscated script shows an unblurred copy of the invoice as a decoy while it downloads and installs action1.msi.
  • The installed agent carries CustomerId 49b18106-681d-456a-b098-092e2818c09a and connects to Action1's cloud at server[.]na-2.action1[.]com.
  • A second sample posing as a DHL document used an HTA script inside a ZIP archive and delivered the same MSI.

Why it matters

  • constraint Hash and reputation checks cannot separate this agent from a sanctioned Action1 install; the difference is whether anyone approved the deployment and whose CustomerId it carries.
  • exposure Organisations that already allow Action1 traffic for their own IT team have left the same outbound path open to this agent, with only the tenant behind it different.
  • precedent With two RMM brands behind one lure in a few days, a list of known-abused tools will trail the next swap, while an allowlist of approved RMM software already covers it.

The link is inside the PDF. Mertens, a senior handler at the SANS Internet Storm Center, found "OpenAction" and "URI" keywords in the attachment, with a page-sized link annotation behind them [1][2]. "This is a common trick to avoid writing URLs in email bodies that can be easily detected," he wrote [3]. We'd expect mail filters that score URLs in the message body to let these emails through.

The payload makes no attempt to evade antivirus. The MSI holds four files, among them action1_remote_exe and main_service_exe, and VirusTotal reported none of them as malicious [6]. They are Action1's own binaries, signed with an "Action1 Corporation" certificate that expired in May 2026 [7]. The agent persists as a service named A1Agent that runs `C:\Windows\Action1\action1_agent.exe` [8]. Its configuration sits under `HKLM\Software\Action1\Agent`, in values named CustomerId, Certificate, PrivateKey, MSI and INSTALLDIR [9].

"We are facing here the same behaviour: the threat actor abuse the cloud infrastructure of the company developing the RMM tool, probably using a free/test account," Mertens wrote [11]. The trial account is his assessment, and he hedges it with "probably" [11].

We think this is cheap to stop at an organisation that does not use Action1. There, an A1Agent service, a `C:\Windows\Action1` directory or a connection to server[.]na-2.action1[.]com counts as a finding with no other evidence needed [8][10]. Both payload hosts in the diary were vercel.app subdomains [13].

Mertens opened the diary with "It seems that a trend started" [15]. In our view the operator can swap the script wrapper and the RMM brand freely, since the HTA variant still ended at the identical MSI [12]. The diary does not name an actor or say whether the VBS runs without a further click from the victim.

What to watch

  • Action1 action against the account behind CustomerId 49b18106-681d-456a-b098-092e2818c09a, or new limits on free and trial tenants.
  • A third RMM product appearing behind the same fake-invoice PDF and vercel.app staging.
  • Any report tying the ScreenConnect and Action1 waves to one operator, or giving victim counts.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence72
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Xavier Mertens, Senior ISC Handler at SANS, reported a phishing campaign in which an email delivers a fake PDF invoice that leads to installation of the Action1 RMM agent.

    ReportedSupportedSource: Xavier Mertens, SANS Internet Storm Center diaryView cited source
  2. [2]

    The PDF contains OpenAction and URI keywords; a link annotation covering the page points to hxxps://up-theta-rose.vercel[.]app/adobe_new_update.vbs, and the URL is visited thanks to the OpenAction when the PDF is opened.

    ReportedSupportedSource: Xavier Mertens, SANS ISCView cited source
  3. [3]

    "This is a common trick to avoid writing URLs in email bodies that can be easily detected."

    ReportedSupportedSource: Xavier Mertens, SANS ISCView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. isc.sans.edu

    1 article · October 9, 2026

    https://isc.sans.edu/diary/33400

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories