In October, Cybersecurity and Infrastructure Security Agency (CISA) identified a widespread cyber campaign involving the malicious use of legitimate RMM software. Specifically, criminal actors sent phishing emails that led to the download of legitimate RMM software – ScreenConnect (now ConnectWise Control) and AnyDesk – which the actors used in a refund scam to steal money from victim bank accounts.
Although this campaign appears financially motivated, CISA, National Security Agency (NSA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) – authors of a Cybersecurity Advisory (CSA) – feel it could lead to additional types of malicious activity.
For example, the actors could sell victim account access to other cyber criminals or advanced persistent threat (APT) actors.
This campaign highlights the threat of malicious cyber activity associated with legitimate RMM software: After gaining access to the target network via phishing or other techniques, malicious cyber actors – from cybercriminals to nation-state sponsored APTs – are known to use legitimate RMM software as a backdoor for persistence and/or command and control (C2).
Using portable executables of RMM software provides a way for actors to establish local user access without the need for administrative privilege and full software installation – effectively bypassing common software controls and risk management assumptions.
The agencies encourage network defenders to review the Indicators of Compromise (IOCs) and Mitigations sections of the CSA and apply the recommendations to protect against malicious use of legitimate RMM software.
The authoring organizations assess since at least June, threat actors have sent help desk-themed phishing emails to federal civilian executive branch (FCEB) staff’s personal, and government email addresses. The emails either contain a link to a “first-stage” malicious domain or prompt the recipients to call the cybercriminals, who then try to convince the recipients to visit the first-stage malicious domain.
A recipient visiting the first-stage malicious domain triggers the download of an executable. The executable then connects to a “second-stage” malicious domain, from which it downloads additional RMM software.
CISA noted the actors did not install downloaded RMM clients on the compromised host. Instead, the actors downloaded AnyDesk and ScreenConnect as self-contained, portable executables configured to connect to the actor’s RMM server.
Click here to view the entire CSA.

