Fake Invoice PDFs Install Action1 Remote-Access Agent

Daniel Zimmermann
6 Min Read
Invoice conceals remote access
A document lure turns a reading request into unauthorized remote access.

A fake payment PDF can show a convincing receipt while a script installs a remote-management agent in the background. In an October 6 report, SANS Internet Storm Center researcher Xavier Mertens traced two document lures to an Action1 installer: one posed as a payment confirmation, the other as a DHL document. The trick was not a flaw in Action1. It was getting a recipient to accept software installation as part of reading a document.

If an invoice asks you to download an Adobe update, run a .vbs file or open an .hta script, stop. The important boundary is the move from viewing a document to executing code.

The unreadable receipt was the bait

Mertens examined an attachment named Transaction Receipt.pdf. Its visible message claimed that an Adobe update was needed to view the PDF. The receipt underneath was blurred, making the supposed update look like a prerequisite for reading the payment details.

Fake Adobe update message covers a blurred payment receipt
The blurred receipt asks for an Adobe update. Source: Xavier Mertens / SANS Internet Storm Center, October 6, 2026.

The PDF contained an opening action and a web link leading to a VBScript file disguised as an Adobe update. That moved the delivery URL out of the email body and into the attachment. Mertens reports that the opening action visits the URL; the report does not establish that every PDF reader automatically executes the downloaded script. Reaching a script download and running it are different events.

Example

Subject: Payment confirmation
Sender: Billing desk — billing [at] example [dot] invalid
Message: Hello, Please find the payment confirmation in the attached document.
Attachment: Transaction Receipt.pdf

Example email with Transaction Receipt PDF attachment
Example: a payment-confirmation attachment email.

The email above is an illustration. The source documents the attachment and its Adobe-update lure, rather than this exact sender or email wording.

A readable document concealed a second job

The downloaded VBScript had two roles. It displayed an unblurred PDF as a decoy and, in parallel, downloaded and installed an MSI package containing Action1 components. Showing the document gave the recipient a reason to believe the requested update had worked. The background installation was the consequential part.

In a second sample, a DHL-themed PDF led to a ZIP archive containing an HTA script, which delivered the same MSI. The packaging changed, but the trust decision stayed the same: a document-reading request was turned into permission to run software.

That pattern also appears in the separate MSP360 and ScreenConnect invitation case. The connection is the abuse of legitimate remote-access software, not evidence that the campaigns share an operator.

Why legitimate files still matter in an unauthorized install

Mertens found four Action1 files that VirusTotal did not flag as malicious in his check. He also observed an Action1 Corporation signing certificate that had expired in May 2026. Neither observation establishes that the installation was authorized: legitimate software can still serve an attacker when it is enrolled through a deceptive document.

The installation created the A1Agent service, displayed as Action1 Agent, running C:\Windows\Action1\action1_agent.exe. The researcher identified an Action1 customer identifier in HKLM\Software\Action1\Agent and a connection to the vendor’s cloud infrastructure. He suggested a free or test account might have been used; that account type was not confirmed.

An Action1 service on a managed work PC can be legitimate. Its name alone is not a malware verdict. The useful question is whether your IT team deployed it, and whether its installation time matches a suspicious document you opened or software you ran. The report does not demonstrate a particular victim’s files were stolen or that ransomware followed.

Act according to what actually ran

If you only received the email, report it and delete it. If you downloaded a script but did not run it, do not execute it to investigate. If you ran the script or installer on a work device, contact IT and give them the attachment, message and approximate time; they can check deployment records and preserve evidence before removing an agent.

On a personal Windows PC, an unwanted agent or recurring security alert warrants cleanup. Removing a visible file can leave a service, loader, scheduled task or bundled component behind. Download and install Gridinsoft Anti-Malware, update its database, run a Full Scan, review and remove detected threats, then restart. A scan can look for malicious leftovers; it cannot revoke an attacker’s accounts or prove that no access occurred.

Scan files downloaded from this scam.

If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.

Scan downloads from this scam

The telling detail in this case is the readable PDF: getting the document you expected was compatible with an unauthorized installation happening at the same time.

References

  1. Xavier Mertens. More RMM Tools In the Wild. SANS Internet Storm Center, October 6, 2026; accessed October 7, 2026.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?