RAT

TrustConnect

TrustConnect (also marketed as TrustConnect Agent) is a commodity Remote Access Trojan distributed as Malware-as-a-Service that masquerades as a legitimate remote management and remote support agent. The operators sell access for approximately $300/month (Bitcoin/USDT) and ship branded installer variants that impersonate legitimate software (Adobe Reader, Microsoft Teams, Zoom, Google Meet, etc.) so victims download what looks like an installer but receive a fully featured RAT. Proofpoint observed TrustConnect delivered through email lures (bid invitations, tax notifications, document shares, government-themed messages) and used as a beachhead to deploy ScreenConnect, Level RMM, and hands-on-keyboard activity within minutes of installation. The operators registered the EV code-signing certificate "TrustConnect Software PTY LTD" through Certum (revoked 2026-02-06), and after disruption activity in February 2026 they pivoted to a successor named "DocConnect" / "SHIELD OS" hosted on networkservice[.]cyou.

Tool overview

Category
RAT
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
No - sold as Malware-as-a-Service (~$300/month, Bitcoin or USDT)
Verification required
Code-signed with Certum Extended Validation certificate issued to "TrustConnect Software PTY LTD" (revoked 2026-02-06)
Supported platforms
Windows

Capabilities

Remote desktop streaming over WebSocketFull keyboard and mouse controlScreen recordingFile transfer (browse, pull, upload)Arbitrary command executionPowerShell loader / one-liner deploymentSystem information gatheringMulti-display switchingOperator activity hiding from victimTelegram bot notifications for device connect/disconnectTwo-factor authentication for operator consoleUsed to deploy follow-on RMM tooling (ScreenConnect, Level RMM)

Executables & installation paths

Filename
TrustConnectAgent.exe
OriginalFileName
TrustConnectAgent.dll
Description
TrustConnect Agent service binary (.NET 8 single-file executable, ~35 MB). Operators ship TrustConnect under per-tenant branded installer variants that impersonate legitimate software (Adobe Reader, Microsoft Teams, Zoom Workspace, Google Meet, Airtable, plus generic Installer / Proposal / SpecialEvents lures) — these filenames are NOT listed as detection inputs here because they collide with the legitimate products' binary names and would produce FPs downstream; rely instead on the TrustConnect-specific signer chain ("TrustConnect Software PTY LTD"), Run-key value pattern (TrustConnectAgent_<random>), service description suffix ("… - Remote Support Agent"), and C2 endpoints below.
Filename
DocConnect.Agent.exe
OriginalFileName
Not recorded
Description
Successor variant ("DocConnect" / "SHIELD OS") observed after February 2026 disruption

Installation paths

C:\Program Files\TrustConnect Agent\TrustConnectAgent.exe
C:\Program Files\TrustConnect Agent\*
C:\ProgramData\TrustConnect\*
*\TrustConnectAgent.exe
TrustConnectAgent.exe
DocConnect.Agent.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\TrustConnect Agent\TrustConnectAgent.exe
Description
TrustConnect Agent service binary (default install path)
OS
Windows
File
C:\Program Files\TrustConnect Agent\config.json
Description
TrustConnect Agent configuration file written at install
OS
Windows
File
C:\ProgramData\TrustConnect\*\config.json
Description
Per-token agent configuration (token subdirectory maps victim to operator org ID)
OS
Windows
File
C:\ProgramData\TrustConnect\*\device.id
Description
36-byte device GUID file used for C2 registration
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
TrustConnect Agent
ImagePath
"C:\\Program Files\\TrustConnect Agent\\TrustConnectAgent.exe"
Description
Service installation event from `sc.exe create "TrustConnect Agent" binPath= "..." start= auto DisplayName= "TrustConnect Agent"`. The service description is set to "TrustConnect Agent - Remote Support Agent". Branded variants register the service under the impersonated product name (e.g., "Adobe Acrobat Reader") with the same "Remote Support Agent" description suffix.
EventID
4697
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
ServiceName
TrustConnect Agent
Description
Security-audit service installation event corresponding to the TrustConnect Agent service create.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\TrustConnect Agent
Description
Service registration created by the agent installer (Start=2 / auto, ImagePath points at TrustConnectAgent.exe).
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrustConnect Agent
Description
Uninstall entry written by the installer (Publisher value reads "TrustConnect Software Ltd", InstallLocation is C:\Program Files\TrustConnect Agent).
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TrustConnectAgent_*
Description
Run-key persistence value with a randomized per-token suffix (observed examples include TrustConnectAgent_QBt4muaH and TrustConnectAgent_POOL04-2). Value data is the full path to the agent binary.
Path
HKLM\SOFTWARE\Classes\AppID\TrustConnectAgent.exe
Description
COM AppID registration created by the agent installer.

FORENSIC EVIDENCE

Network artifacts

Description
Primary command-and-control domain (registered 2026-01-12 via NICENIC; A record 178.128.69.245 then 185.182.187.10).
Domains
  • trustconnectsoftware.com
Ports
  • 443
Description
REST C2 endpoints used by the agent for registration, heartbeat, command pull, command results, file browsing/pull, and binary update. URLs include /api/agents/register, /api/agents/heartbeat, /api/agent-commands/<DEVICE_GUID>, /api/agent-commands/result, /api/files/browse/pull, /api/files/pull, /api/files/upload, /api/devices, /api/commands/run, /api/installer/script, /agent-update.
Domains
  • trustconnectsoftware.com
Ports
  • 443
Description
WebSocket endpoints used for live remote desktop streaming and recording (/ws/screen, /ws/viewer, /api/screen/start, /api/recordings/chunk/<id>).
Domains
  • trustconnectsoftware.com
Ports
  • 443
Description
Operator console / authentication endpoints (/api/auth/login, /api/auth/verify-login, /api/admin/devices/online).
Domains
  • trustconnectsoftware.com
Ports
  • 443
Description
Successor "DocConnect" / "SHIELD OS" infrastructure observed after February 2026 disruption (React SPA backend, Supabase, SignalR transport).
Domains
  • networkservice.cyou
Ports
  • 443
Description
TrustConnect C2 IP addresses (DigitalOcean and Contabo).
Domains
Not recorded
Ports
  • 443

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_files_sigma.yml
Description
Detects potential file activity of TrustConnect RAT
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_network_sigma.yml
Description
Detects potential network activity of TrustConnect RAT
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_processes_sigma.yml
Description
Detects potential process activity of TrustConnect RAT
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_registry_sigma.yml
Description
Detects potential registry activity of TrustConnect RAT

References

Acknowledgements

Person
mikehemming
Handle
@mikehemming
Person
jaalmaaa
Handle
@jaalmaaa
Person
Michael Haag
Handle
@MHaggis