Skip to content
Threat Feed
low advisory

Detection of RMM Software Execution from Commonly Abused Web Services

Adversaries are actively abusing legitimate, digitally signed remote monitoring and management (RMM) software, often delivered via public cloud storage or file-sharing services, to maintain persistent command-and-control access in Windows environments.

Threat actors frequently leverage legitimate remote monitoring and management (RMM) tools as a mechanism for persistent command-and-control (C2) access. By downloading these dual-use tools from public web services, cloud hosting platforms, or file-sharing sites, attackers bypass traditional perimeter filters. The observed behavior involves the execution of digitally signed binaries - such as those from ScreenConnect, TeamViewer, or AnyDesk - in scenarios inconsistent with established administrative or organizational deployment workflows. This technique is commonly employed during the post-exploitation phase of social engineering campaigns or broader intrusions to facilitate remote desktop control and exfiltration. Because these tools are often legitimate and signed by reputable publishers, defenders must prioritize context-aware detections that correlate the software's origin URL and execution path against known administrative baselines.

Attack Chain

  1. Attacker stages a legitimate, signed RMM installer on a public web service (e.g., GitHub, Dropbox, or S3 bucket).
  2. The victim is lured to the malicious URL via a spear-phishing link or a compromised document.
  3. The RMM binary is downloaded to the victim's host, often inheriting a "Zone.Identifier" alternate data stream indicating an internet origin.
  4. The attacker executes the downloaded RMM binary, triggering a process start event.
  5. The RMM tool establishes an outbound connection to the attacker's controller or the vendor's infrastructure for remote access.
  6. The attacker uses the persistent remote desktop session to perform internal reconnaissance, credential theft, or data exfiltration.

Impact

Successful abuse of RMM software grants attackers full interactive control over the host. If left undetected, this access allows for long-term persistence, lateral movement, and data theft. These campaigns have been observed across various sectors as attackers evolve their delivery methods to include victim filtering and trojanized installers.

Recommendation

  1. Deploy behavioral detection rules that correlate process execution with origin URL telemetry, specifically monitoring for RMM tools sourced from non-corporate domains.
  2. Review the list of monitored RMM publishers identified in the detection logic and validate them against internal IT administrative tools.
  3. Implement strict egress filtering to restrict unauthorized remote access tools from reaching known C2 infrastructure or non-essential external endpoints.
  4. Investigate any process execution of software signed by the publishers listed in the detection criteria that does not align with authorized software distribution or support tickets.

Immediate actions

Review RMM tool usage in the environment and compare against authorized IT management software.

SOC 48h

Threat Hunt

Search for unsigned or rarely seen RMM binaries downloaded from domains like github.com, files.slack.com, or mega.nz.

T1219 medium high confidence hunt now

Data: Process creation events with origin_url metadata

Mitigations

Restrict execution of RMM tools via AppLocker or EDR policies to only allow approved administrative tools.

medium_term IT Operations