Explainer
Remote access tools
Legitimate remote-management software (RMM) and remote access trojans abused to control machines while blending into ordinary IT activity.
In this section
What it is
Remote access tools let someone control a computer from elsewhere. Two kinds matter to defenders. Remote access trojans (RATs) are purpose-built malware, such as VenomRAT. Remote monitoring and management (RMM) products such as ScreenConnect, AnyDesk or TeamViewer are legitimate IT software that criminals install or hijack. Abuse of legitimate RMM is now the bigger concern because it is signed, trusted and often already allowed on the network.
How it gets in
Proofpoint reported in 2025 that more criminals were sending RMM installers directly as the first payload in email campaigns, with ScreenConnect the most prominent, alongside Atera, NetSupport and others. Lures typically impersonate government agencies or payment notices. CISA advisory AA23-025A described help desk-themed phishing that led federal staff to run portable versions of ScreenConnect and AnyDesk, which launch without installation or admin rights. Social engineering crews such as Scattered Spider call help desks to reset credentials, then install remote tools; CISA's advisory on the group lists ScreenConnect, AnyDesk, TeamViewer, Splashtop and Tactical.RMM among the software it used.
What it does
Once connected, an attacker has the same hands-on control as an IT administrator: running commands, moving files, installing more tools, and reaching other systems. Because the traffic belongs to a known product, it may not trigger antivirus alerts, Proofpoint noted.
Notable activity in 2025-2026
Operation Endgame's November 2025 phase targeted VenomRAT, and The Hacker News reported its main suspect was arrested in Greece on 3 November 2025. Proofpoint said NetSupport, historically the most common RMM in its data, fell away in 2024 as ScreenConnect and other products became more prominent, a trend it expected to continue.
How it is used downstream
Remote access is the bridge between an initial foothold and a full intrusion. Attackers use it for data theft, fraud such as refund scams, and staging ransomware. CISA's AA23-025A case ended in a refund scam; CISA's updated Scattered Spider advisory, revised in July 2025, links the group's intrusions to data extortion and to ransomware including DragonForce. Controlling which remote tools may run, and verifying who asks the help desk for access, removes much of that path.
Detect and contain
Detection signals
- RMM agents not on the approved-software list, including portable executables run from user folders
- Remote sessions outside change windows or from unfamiliar accounts
- New RMM installs shortly after a help-desk password or MFA reset
Reduce the blast radius
- Allow-list one approved RMM product and block the rest at the endpoint and firewall
- Require out-of-band verification for help-desk credential and MFA resets
- Alert on RMM installs and connections via EDR and network monitoring
Questions people ask
What is a remote access trojan (RAT)?
A remote access trojan is malware that gives an attacker hidden control of an infected computer, letting them run commands, steal files, log keystrokes or install more malware. Unlike legitimate remote support software, it is designed to hide from the user. VenomRAT, targeted by police in November 2025, is one example.
Why do hackers use legitimate remote access software?
Tools like ScreenConnect or AnyDesk are signed, widely used and often already allowed through firewalls, so they rarely trigger antivirus alerts. They give the same control as custom malware without the attacker having to build or hide it. Portable versions can even run without installation or administrator rights, according to CISA.
How can I tell if someone is remotely accessing my computer?
Warning signs include a remote support program you did not install, the mouse moving on its own, unexpected pop-ups asking to approve a connection, and new icons in the system tray. On company devices, check with IT before approving any remote session, and never install remote software because an unsolicited caller or email asked you to.
Desk coverage
- Aadhaar or PAN leaked in a data breach? How to lock it down and check for misuse
- Bank account frozen by cyber police? What to do if you received tainted money without knowing
- How to get money back after cyber fraud: the real routes, the odds and 'recovery' scams
- Deepfake investment ads in India: what they are, who has been faked, and how to spot one
Further reading
- CISA — Protecting against malicious use of RMM software (AA23-025A)
- CISA — Scattered Spider advisory (AA23-320A, updated Jul 2025)
- Proofpoint — RMM tooling increasingly an attacker's first choice (7 Mar 2025)
- The Hacker News — Operation Endgame dismantles Rhadamanthys, Venom RAT and Elysium botnet (Nov 2025)