TrustConnect is a fake RMM that leads to C2

The IOCs from this Proofpoint report are on point (pun intended). Confirmed independent sighting, including hands-on-keyboard enumeration via PowerShell launched from dllhost.exe as an injected process.