Skip to main content

Threats Tagged 'remote access tool'

View all threats tagged with 'remote access tool'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: remote access tool

Threats Tagged 'remote access tool'

Click on any threat for detailed analysis and mitigation recommendations

A campaign uses fake websites impersonating CNN, Stremio, and Avast to distribute legitimate remote administration software O&O Syspectr pre-linked to attacker accounts. The lookalike sites closely mimic authentic homepages and trick Windows users into downloading installers that appear legitimate but grant attackers remote access to victim computers. Additional fake sites use cryptocurrency mining game lures to distribute the same tool. All installers are digitally signed legitimate software, making antivirus detection difficult. The campaign uses multiple Syspectr account IDs embedded in filenames, with CNN, Avast, and Stremio lures sharing one account while crypto-mining lures use another. O&O Software responded by disabling Remote Desktop and Remote Console access for free accounts and suspending the abusive accounts.

Join the discussion

A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

Join the discussion

In February 2026, an attack chain was discovered that utilized a fraudulent Adobe Acrobat Reader download page to deceive victims into installing ConnectWise's ScreenConnect, a legitimate remote access tool exploited for malicious purposes. The attack employs sophisticated evasion techniques including heavy obfuscation, .NET reflection for in-memory payload execution, and dynamic code construction. A VBScript loader initiates the chain by downloading and executing obfuscated PowerShell commands that compile C# code entirely in memory. The loader manipulates the Process Environment Block to masquerade as legitimate Windows processes and abuses auto-elevated COM objects to bypass User Account Control without user prompts. This multi-layered approach successfully evades signature-based defenses and hinders forensic analysis while ultimately deploying ScreenConnect for unauthorized remote access.

Join the discussion

A malicious email campaign exploits workforce anxieties by disguising itself as internal HR announcements about layoffs. The emails contain a RAR archive with a double-extension executable masquerading as a PDF document. Upon execution, the file deploys Remcos RAT, a remote access tool, which establishes persistence, collects system information, and prepares the infected host for remote access. The malware uses NSIS compilation to conceal its intent and creates configuration files and registry entries for victim identification and persistence. The campaign highlights the ongoing exploitation of current organizational trends by threat actors to gain initial access to targeted systems.

Join the discussion

North Korean threat actors Kimsuky and Lazarus have deployed new sophisticated malware toolsets named HttpTroy and an upgraded BLINDINGCAN variant. HttpTroy is a backdoor delivered via a VPN invoice-themed attack, involving a dropper and loader (MemLoad), granting extensive system control. Lazarus's upgraded BLINDINGCAN is delivered through a new Comebacker malware variant, targeting victims in Canada. Both toolsets use advanced obfuscation, stealth techniques, and layered evasion to avoid detection. These attacks highlight DPRK's evolving cyber espionage capabilities. Although currently observed targeting South Korea and Canada, European organizations could be at risk due to geopolitical tensions and similar attack methodologies. No known exploits in the wild have been reported yet. Mitigation requires targeted detection of these toolsets, network monitoring for associated indicators, and enhanced endpoint defenses. The threat is assessed as medium severity due to its espionage focus, stealth, and complexity, but limited current scope and no public CVSS score.

Join the discussion

The ClickFix social engineering technique has gained popularity among threat actors, targeting thousands of devices globally. It tricks users into executing malicious commands on their devices by exploiting their tendency to solve minor technical issues. The technique often impersonates legitimate brands and combines with delivery vectors like phishing and malvertising. ClickFix campaigns typically lead users to a visual lure, such as a landing page, instructing them to run commands in the Windows Run dialog. This user interaction element helps bypass conventional security solutions. Various malware, including infostealers and remote access tools, are delivered through ClickFix attacks. The technique has evolved to target macOS users and is being sold as part of malware kits on hacker forums.

Join the discussion

A deceptive email containing a fake Zoom meeting invitation has been identified. Clicking the 'join' button leads to a website prompting users to install a purported Zoom client update. The downloaded executable, 'Session.ClientSetup.exe', is actually malware that installs an MSI package. This package deploys ScreenConnect, a remote access tool, allowing attackers to gain unauthorized access to the victim's computer. The malware establishes persistence by installing itself as a service and connects to a command and control server at tqtw21aa.anondns.net on port 8041. Users are advised to exercise caution when receiving unexpected Zoom invitations or update prompts.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: remote access tool
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses