TrustConnect
TrustConnect (also marketed as TrustConnect Agent) is a commodity Remote Access Trojan distributed as Malware-as-a-Service that masquerades as a legitimate remote management and remote support agent. The operators sell access for approximately $300/month (Bitcoin/USDT) and ship branded installer variants that impersonate legitimate software (Adobe Reader, Microsoft Teams, Zoom, Google Meet, etc.) so victims download what looks like an installer but receive a fully featured RAT. Proofpoint observed TrustConnect delivered through email lures (bid invitations, tax notifications, document shares, government-themed messages) and used as a beachhead to deploy ScreenConnect, Level RMM, and hands-on-keyboard activity within minutes of installation. The operators registered the EV code-signing certificate "TrustConnect Software PTY LTD" through Certum (revoked 2026-02-06), and after disruption activity in February 2026 they pivoted to a successor named "DocConnect" / "SHIELD OS" hosted on networkservice[.]cyou.
Tool overview
- Category
- RAT
- Research authors
- @MHaggis
- Created
- 2026-05-04
- Last modified
- 2026-05-04
- Privileges
- SYSTEM
- Free / availability
- No - sold as Malware-as-a-Service (~$300/month, Bitcoin or USDT)
- Verification required
- Code-signed with Certum Extended Validation certificate issued to "TrustConnect Software PTY LTD" (revoked 2026-02-06)
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- TrustConnectAgent.exe
- OriginalFileName
- TrustConnectAgent.dll
- Description
- TrustConnect Agent service binary (.NET 8 single-file executable, ~35 MB). Operators ship TrustConnect under per-tenant branded installer variants that impersonate legitimate software (Adobe Reader, Microsoft Teams, Zoom Workspace, Google Meet, Airtable, plus generic Installer / Proposal / SpecialEvents lures) — these filenames are NOT listed as detection inputs here because they collide with the legitimate products' binary names and would produce FPs downstream; rely instead on the TrustConnect-specific signer chain ("TrustConnect Software PTY LTD"), Run-key value pattern (TrustConnectAgent_<random>), service description suffix ("… - Remote Support Agent"), and C2 endpoints below.
- Filename
- DocConnect.Agent.exe
- OriginalFileName
- Not recorded
- Description
- Successor variant ("DocConnect" / "SHIELD OS") observed after February 2026 disruption
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\TrustConnect Agent\TrustConnectAgent.exe
- Description
- TrustConnect Agent service binary (default install path)
- OS
- Windows
- File
- C:\Program Files\TrustConnect Agent\config.json
- Description
- TrustConnect Agent configuration file written at install
- OS
- Windows
- File
- C:\ProgramData\TrustConnect\*\config.json
- Description
- Per-token agent configuration (token subdirectory maps victim to operator org ID)
- OS
- Windows
- File
- C:\ProgramData\TrustConnect\*\device.id
- Description
- 36-byte device GUID file used for C2 registration
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- TrustConnect Agent
- ImagePath
- "C:\\Program Files\\TrustConnect Agent\\TrustConnectAgent.exe"
- Description
- Service installation event from `sc.exe create "TrustConnect Agent" binPath= "..." start= auto DisplayName= "TrustConnect Agent"`. The service description is set to "TrustConnect Agent - Remote Support Agent". Branded variants register the service under the impersonated product name (e.g., "Adobe Acrobat Reader") with the same "Remote Support Agent" description suffix.
- EventID
- 4697
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- TrustConnect Agent
- Description
- Security-audit service installation event corresponding to the TrustConnect Agent service create.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\TrustConnect Agent
- Description
- Service registration created by the agent installer (Start=2 / auto, ImagePath points at TrustConnectAgent.exe).
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrustConnect Agent
- Description
- Uninstall entry written by the installer (Publisher value reads "TrustConnect Software Ltd", InstallLocation is C:\Program Files\TrustConnect Agent).
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TrustConnectAgent_*
- Description
- Run-key persistence value with a randomized per-token suffix (observed examples include TrustConnectAgent_QBt4muaH and TrustConnectAgent_POOL04-2). Value data is the full path to the agent binary.
- Path
- HKLM\SOFTWARE\Classes\AppID\TrustConnectAgent.exe
- Description
- COM AppID registration created by the agent installer.
FORENSIC EVIDENCE
Network artifacts
- Description
- Primary command-and-control domain (registered 2026-01-12 via NICENIC; A record 178.128.69.245 then 185.182.187.10).
- Domains
- trustconnectsoftware.com
- Ports
- 443
- Description
- REST C2 endpoints used by the agent for registration, heartbeat, command pull, command results, file browsing/pull, and binary update. URLs include /api/agents/register, /api/agents/heartbeat, /api/agent-commands/<DEVICE_GUID>, /api/agent-commands/result, /api/files/browse/pull, /api/files/pull, /api/files/upload, /api/devices, /api/commands/run, /api/installer/script, /agent-update.
- Domains
- trustconnectsoftware.com
- Ports
- 443
- Description
- WebSocket endpoints used for live remote desktop streaming and recording (/ws/screen, /ws/viewer, /api/screen/start, /api/recordings/chunk/<id>).
- Domains
- trustconnectsoftware.com
- Ports
- 443
- Description
- Operator console / authentication endpoints (/api/auth/login, /api/auth/verify-login, /api/admin/devices/online).
- Domains
- trustconnectsoftware.com
- Ports
- 443
- Description
- Successor "DocConnect" / "SHIELD OS" infrastructure observed after February 2026 disruption (React SPA backend, Supabase, SignalR transport).
- Domains
- networkservice.cyou
- Ports
- 443
- Description
- TrustConnect C2 IP addresses (DigitalOcean and Contabo).
- Domains
- Not recorded
- Ports
- 443
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_files_sigma.yml
- Description
- Detects potential file activity of TrustConnect RAT
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_network_sigma.yml
- Description
- Detects potential network activity of TrustConnect RAT
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_processes_sigma.yml
- Description
- Detects potential process activity of TrustConnect RAT
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/trustconnect_registry_sigma.yml
- Description
- Detects potential registry activity of TrustConnect RAT
References
- https://www.proofpoint.com/us/blog/threat-insight/dont-trustconnect-its-a-rat
- https://github.com/magicsword-io/LOLRMM/issues/157
- https://github.com/magicsword-io/LOLRMM/issues/150
- https://www.virustotal.com/gui/file/cee6895f7df01da489c10bf5b83770ceede79ed4e1c8c4f8ea9787a4d035c79b
- https://www.virustotal.com/gui/file/edde2673becdf84e3b1d823a985c7984fec42cb65c7666e68badce78bd0666c0
- https://www.virustotal.com/gui/domain/trustconnectsoftware.com
Acknowledgements
- Person
- mikehemming
- Handle
- @mikehemming
- Person
- jaalmaaa
- Handle
- @jaalmaaa
- Person
- Michael Haag
- Handle
- @MHaggis