Files
iimp0ster-detection-chokepo…/chokepoints/initial-access/renamed-rmm-tools.yml
T
imposterandClaude Sonnet 4.6 d312295365 Fix YAML scanner errors: quote Name values containing colons
Five Name fields containing ": " were parsed as YAML mapping separators.
Wrapped affected values in double-quotes across three chokepoint files.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-07 16:28:26 -07:00

221 lines
14 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
Name: Renamed RMM Tools
Id: b3d5e7f9-1a2c-4b6d-8e0f-3c5a7b9d1e2f
MitreIds:
- T1219.002
Tactics:
- Command and Control
Techniques:
- "Remote Access Software"
DetectionPriority: HIGH
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: >
Legitimate remote management and monitoring (RMM) tools are renamed or
masqueraded to appear as trusted applications (tax documents, invoices, IT
support tools) and delivered via browser download. Once executed, the RMM
establishes persistent command-and-control to attacker infrastructure while
appearing to be a signed, legitimate binary. Because the binary is legitimately
signed by the vendor, many security tools will not flag it. The chokepoint is
the browser download, file masquerading, user execution, and outbound connection
to RMM infrastructure — all of which are required regardless of which RMM tool
is used.
LastUpdated: "2026-03-07"
Author: "@iimp0ster"
Variations:
- Name: AnyDesk
FirstSeen: "2020"
Status: Declining
Notes: "Common masquerade names: invoice.exe, tax_form.exe, SSN_verification.exe; February 2024 production server breach resulted in source code and code signing certificate theft — certificate revoked, driving threat actor migration to other tools"
- Name: TeamViewer
FirstSeen: "2019"
Status: Active
Notes: "Common masquerade names: update.exe, system_check.exe"
- Name: ScreenConnect (ConnectWise)
FirstSeen: "2022"
Status: Active
Notes: "Common masquerade names: support_tool.exe, IT_access.exe; now primary choice for renamed-binary delivery; February 2024 CVE-2024-1709 (auth bypass) + CVE-2024-1708 (path traversal) enabled direct server exploitation by LockBit, Black Basta, and Bl00dy — 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct server exploitation"
- Name: UltraViewer
FirstSeen: "2023"
Status: Active
Notes: "Common masquerade names: security_scan.exe, verify.exe"
- Name: RustDesk
FirstSeen: "2024"
Status: Emerging
Notes: Open-source; self-hosted infrastructure makes domain blocking ineffective
- Name: SimpleHelp
FirstSeen: "2025-Q1"
Status: Active
Notes: "CVE-2024-57727 (path traversal), CVE-2024-57726 (privilege escalation), CVE-2024-57728 (arbitrary file upload) disclosed January 2025; exploited in the wild since January 22, 2025 as ransomware initial access vector; DragonForce deployed via it; CISA advisory AA25-163A issued June 2025; CISA KEV listed February 2025"
- Name: NetSupport Manager
FirstSeen: "2023"
Status: Active
Notes: "Heavily abused by TA571 throughout 2024–2025; frequently delivered as the payload of ClickFix clipboard campaigns; one of the most common RMM payloads in commodity phishing operations"
- Name: Atera
FirstSeen: "2023"
Status: Active
Notes: "Used by MuddyWater (Iran/TA450) in nation-state campaigns; also deployed post-compromise as secondary RMM after ScreenConnect CVE-2024-1709 exploitation in European targets"
- Name: RMM-to-RMM Deployment
FirstSeen: "2024"
Status: Active
Notes: >
One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for
redundancy — if one is removed, the other maintains access
Prerequisites:
- Site to host payload (attacker-controlled or compromised legitimate site)
- Social engineering pretext (tax, invoice, SSN, IT support, e-invite)
- RMM tool binary (legitimately signed vendor software, just renamed)
- User must download and execute the binary via browser
EvolutionTimeline:
- Date: "2019"
Event: TeamViewer and AnyDesk adoption in social engineering campaigns
Change: Legitimate RMM binaries adopted as an initial access alternative to malware
DetectionImpact: New pattern — signed binaries evading hash-based detection
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2022-Q1"
Event: ScreenConnect becomes primary campaign tool
Change: Shift to ConnectWise ScreenConnect for a more "professional" appearance
DetectionImpact: No change to core detection pattern
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2023-Q2"
Event: UltraViewer campaigns emerge
Change: Shift to less-known tools to evade AnyDesk-specific detections
DetectionImpact: Tool-agnostic detection becomes critical; vendor name can no longer be relied on
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2024-Q1"
Event: AnyDesk breach + ScreenConnect mass CVE exploitation
Change: AnyDesk production servers breached (code signing cert stolen and revoked); simultaneously CVE-2024-1709 auth bypass enables direct server exploitation of 18,000+ exposed ScreenConnect instances by ransomware groups
DetectionImpact: Browser-download detection insufficient for direct server exploitation; must also monitor RMM server processes for unexpected outbound sessions and lateral movement
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2024-Q3"
Event: RustDesk adoption as self-hosted alternative
Change: Open-source RMM with self-hosted C2; blocklisting known RMM domains no longer works
DetectionImpact: Domain/IP-based blocking bypassed; behavior detection essential
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2025-Q1"
Event: SimpleHelp CVE exploitation as ransomware initial access
Change: Three critical SimpleHelp vulnerabilities (CVE-2024-57727/57726/57728) exploited by ransomware actors beginning January 2025; marks shift from exploiting client-delivered RMM to exploiting the RMM server infrastructure itself
DetectionImpact: RMM server vulnerability exploitation requires monitoring of RMM server logs and network egress, not just endpoint process/file telemetry
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
- Date: "2024-Q4"
Event: RMM-to-RMM deployment pattern emerges
Change: First RMM is used to deploy a second RMM as a backup persistence mechanism
DetectionImpact: Process creation chain detection required; single-RMM detection insufficient
TheConstant: "Browser download → renamed binary → user execution → outbound RMM connection"
Detections:
- Level: Research
Description: Identify all RMM tool processes running in the environment
LogSources:
- "Sysmon Event ID 1 (Process Creation)"
- "Windows Security Event ID 4688 (Process Creation)"
- "Application inventory / software management telemetry"
Logic: >
Process name matches known RMM tool executables:
anydesk.exe OR screenconnect*.exe OR teamviewer*.exe OR
ultraviewer.exe OR rustdesk.exe OR meshagent.exe OR
connectwisecontrol*.exe
ExpectedFPRate: High
UseCase: Asset inventory; baseline of legitimate RMM usage by IT staff
SigmaRule: sigma-rules/renamed-rmm/research.yml
- Level: Hunt
Description: Detect RMM tool binaries downloaded via browser and executed within minutes
LogSources:
- "Sysmon Event ID 1 (Process Creation)"
- "Sysmon Event ID 11 (File Creation)"
- "Browser download telemetry"
Logic: >
File Created: *.exe
Creating Process: chrome.exe OR firefox.exe OR msedge.exe OR iexplore.exe OR brave.exe
File Path: \Downloads\ OR \Temp\ OR \AppData\Local\Temp\
Then: Process execution within 5 minutes
AND: Product metadata OR original filename matches known RMM vendor
ExpectedFPRate: Medium
UseCase: Hunt for user-initiated RMM downloads; distinguishes IT-deployed from user-downloaded
SigmaRule: sigma-rules/renamed-rmm/hunt.yml
- Level: Analyst
Description: Masqueraded RMM tool with campaign-themed name, downloaded by browser, with immediate outbound connection
LogSources:
- "Sysmon Event ID 1 (Process Creation)"
- "Sysmon Event ID 3 (Network Connection)"
- "Sysmon Event ID 11 (File Creation)"
- "File metadata / version info analysis"
Logic: >
File Created: *.exe via browser (see Hunt logic above)
AND one of:
- File Name contains: "tax" OR "invoice" OR "SSN" OR "SSA" OR "support" OR "verify" OR "secure"
- File Metadata: OriginalFilename = "anydesk.exe" (or other RMM) but current name differs
- File Signer: Known RMM vendor certificate on file with non-RMM name
Network: Outbound connection to RMM infrastructure within 2 minutes of execution
UserContext: Standard user account (not in IT admin group)
ExpectedFPRate: Low
UseCase: SOC alerting; campaign-themed file name detection catches targeted pretexts
SigmaRule: sigma-rules/renamed-rmm/analyst.yml
Intel:
- Name: CISA AA23-025A — Protecting Against Malicious Use of RMM Software
URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
Description: Foundational joint advisory from CISA, NSA, and MS-ISAC documenting malicious RMM use; specifically covers portable executable delivery bypassing software installation controls, AnyDesk and ScreenConnect campaign mechanics
- Name: CISA AA25-163A — Ransomware Actors Exploit SimpleHelp RMM
URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a
Description: June 2025 advisory covering CVE-2024-57727 exploitation by ransomware actors as initial access vector since January 2025; includes IOCs and detection guidance
- Name: Unit 42 — ConnectWise ScreenConnect CVE-2024-1709 Threat Brief
URL: https://unit42.paloaltonetworks.com/connectwise-threat-brief-cve-2024-1708-cve-2024-1709/
Description: Technical analysis of CVE-2024-1709 auth bypass and CVE-2024-1708 exploitation; documents ransomware group adoption and scale of exposed instances
- Name: Huntress — A Series of Unfortunate (RMM) Events
URL: https://www.huntress.com/blog/series-of-unfortunate-rmm-events
Description: Covers RMM-to-RMM chaining, detection evasion patterns, and the broader RMM abuse landscape from an MSP incident response perspective
- Name: "Microsoft — Keys to the Kingdom: RMM Exploits in Human-Operated Intrusions 2024–25"
URL: https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/keys-to-the-kingdom-rmm-exploits-enabling-human-operated-intrusions-in-2024%E2%80%9325/4410903
Description: Microsoft Security Experts analysis of RMM exploitation patterns across incident response engagements; covers both social engineering delivery and direct CVE exploitation vectors
- Name: BleepingComputer — AnyDesk Production Servers Breached
URL: https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/
Description: Documents the February 2024 AnyDesk breach, certificate revocation, and downstream impact on threat actor tooling choices
- Name: MITRE ATT&CK — T1219.002 Remote Desktop Software
URL: https://attack.mitre.org/techniques/T1219/002/
Description: Technique definition, procedure examples including RMM tool abuse, and detection guidance for remote desktop software used as C2
RelatedChokepoints:
- clickfix-techniques
- remote-execution-tools
OsintSources:
- Platform: URLScan
Query: "filename:tax*.exe OR filename:invoice*.exe OR filename:ssn*.exe"
URL: "https://urlscan.io/search/#filename%3Atax*.exe%20OR%20filename%3Ainvoice*.exe%20OR%20filename%3Assn*.exe"
Notes: "Finds download pages serving tax/invoice-themed executables — the most common ClickFix and RMM masquerade pretexts. Expand with 'support*.exe', 'verify*.exe' for additional pretext coverage."
- Platform: Shodan
Query: 'product:"ScreenConnect"'
URL: "https://www.shodan.io/search?query=product%3A%22ScreenConnect%22"
Notes: "Find internet-exposed ScreenConnect instances; cross-reference against known legitimate MSP infrastructure to identify attacker-controlled instances. Useful for CVE-2024-1709 exposure assessment."
- Platform: Censys
Query: 'services.tls.certificate.parsed.subject.common_name: "AnyDesk"'
URL: "https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22AnyDesk%22"
Notes: "Updated Censys v2 field syntax (replaces deprecated ssl: prefix). Identifies infrastructure presenting AnyDesk TLS certificates; useful for correlating attacker-controlled AnyDesk relay infrastructure."
KnownBypasses:
- Bypass: Legitimate business use of the same RMM tool
Mitigation: Maintain allowlist of IT-approved RMM instances and source IPs
Detection: Focus on user-initiated browser downloads rather than all RMM process execution
- Bypass: Self-hosted RMM infrastructure (RustDesk, MeshCentral)
Mitigation: Network-level egress filtering by traffic pattern
Detection: Detect by behavior (browser download + user execution) not by destination domain
- Bypass: Legitimate-looking file names matching IT asset naming conventions
Mitigation: User awareness training; verify download sources with IT
Detection: Combine with file metadata mismatch (OriginalFilename vs. actual name)
- Bypass: Delayed execution (user downloads, executes hours later)
Mitigation: N/A
Detection: Extend correlation time window; correlate on file path rather than time delta
- Bypass: CVE exploitation of internet-exposed RMM servers (no user interaction required)
Mitigation: Patch RMM platforms promptly; restrict RMM management interfaces from internet exposure; subscribe to vendor security bulletins
Detection: "All current detection logic assumes user-initiated browser download — server-side exploitation bypasses it entirely. Monitor RMM server process telemetry for unexpected child processes, lateral movement, and outbound connections to non-RMM destinations. Alert on RMM server processes (ScreenConnect, SimpleHelp) spawning cmd.exe, powershell.exe, or network scanners."
- Bypass: Portable executable delivery (no installation required, bypasses software install controls)
Mitigation: Block unsigned or unapproved portable executables via application control; monitor Downloads/Temp for executable creation
Detection: "CISA AA23-025A specifically highlights that portable executables don't require admin privileges and bypass software installation audit controls. Detection must focus on process execution from user-writable paths rather than relying on install events."