All malware guidance

Explainer

Remote access tools

Legitimate remote-management software (RMM) and remote access trojans abused to control machines while blending into ordinary IT activity.

In this section

What it is

Remote access tools let someone control a computer from elsewhere. Two kinds matter to defenders. Remote access trojans (RATs) are purpose-built malware, such as VenomRAT. Remote monitoring and management (RMM) products such as ScreenConnect, AnyDesk or TeamViewer are legitimate IT software that criminals install or hijack. Abuse of legitimate RMM is now the bigger concern because it is signed, trusted and often already allowed on the network.

How it gets in

Proofpoint reported in 2025 that more criminals were sending RMM installers directly as the first payload in email campaigns, with ScreenConnect the most prominent, alongside Atera, NetSupport and others. Lures typically impersonate government agencies or payment notices. CISA advisory AA23-025A described help desk-themed phishing that led federal staff to run portable versions of ScreenConnect and AnyDesk, which launch without installation or admin rights. Social engineering crews such as Scattered Spider call help desks to reset credentials, then install remote tools; CISA's advisory on the group lists ScreenConnect, AnyDesk, TeamViewer, Splashtop and Tactical.RMM among the software it used.

What it does

Once connected, an attacker has the same hands-on control as an IT administrator: running commands, moving files, installing more tools, and reaching other systems. Because the traffic belongs to a known product, it may not trigger antivirus alerts, Proofpoint noted.

Notable activity in 2025-2026

Operation Endgame's November 2025 phase targeted VenomRAT, and The Hacker News reported its main suspect was arrested in Greece on 3 November 2025. Proofpoint said NetSupport, historically the most common RMM in its data, fell away in 2024 as ScreenConnect and other products became more prominent, a trend it expected to continue.

How it is used downstream

Remote access is the bridge between an initial foothold and a full intrusion. Attackers use it for data theft, fraud such as refund scams, and staging ransomware. CISA's AA23-025A case ended in a refund scam; CISA's updated Scattered Spider advisory, revised in July 2025, links the group's intrusions to data extortion and to ransomware including DragonForce. Controlling which remote tools may run, and verifying who asks the help desk for access, removes much of that path.

Detect and contain

Detection signals

  • RMM agents not on the approved-software list, including portable executables run from user folders
  • Remote sessions outside change windows or from unfamiliar accounts
  • New RMM installs shortly after a help-desk password or MFA reset

Reduce the blast radius

  • Allow-list one approved RMM product and block the rest at the endpoint and firewall
  • Require out-of-band verification for help-desk credential and MFA resets
  • Alert on RMM installs and connections via EDR and network monitoring

Questions people ask

What is a remote access trojan (RAT)?

A remote access trojan is malware that gives an attacker hidden control of an infected computer, letting them run commands, steal files, log keystrokes or install more malware. Unlike legitimate remote support software, it is designed to hide from the user. VenomRAT, targeted by police in November 2025, is one example.

Why do hackers use legitimate remote access software?

Tools like ScreenConnect or AnyDesk are signed, widely used and often already allowed through firewalls, so they rarely trigger antivirus alerts. They give the same control as custom malware without the attacker having to build or hide it. Portable versions can even run without installation or administrator rights, according to CISA.

How can I tell if someone is remotely accessing my computer?

Warning signs include a remote support program you did not install, the mouse moving on its own, unexpected pop-ups asking to approve a connection, and new icons in the system tray. On company devices, check with IT before approving any remote session, and never install remote software because an unsolicited caller or email asked you to.

Further reading