Skip to content
Threat Feed

Tag

Remote-Access

42 briefs RSS
high advisory

Rogue ScreenConnect Clients Distribute Four-Stage VBScript Malware

Threat actors are using compromised ConnectWise ScreenConnect instances to propagate a worm-like, four-stage VBScript infection chain that enables backdooring, UAC bypass, and cryptojacking on connected hosts.

ScreenConnect Remote Access worm social-engineering remote-access malware
1r 6t 4i
high advisory

Worm-like Campaign Leveraging Modified ScreenConnect Clients

Threat actors are using social engineering to deploy modified, backdoored ScreenConnect clients that automate multi-stage payload execution and self-propagation across connected remote hosts.

ScreenConnect remote-access worm lateral-movement
1r 4t 1c updated
critical advisory

Hard-coded Credentials in SmartIT Desktop Manager

SmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.

SmartIT Desktop Manager vulnerability credential-exposure remote-access
1t 1c
critical advisory

CVE-2026-85440: Heap Overflow in MOOS core-moos

A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.

core-moos cve authentication-bypass middleware denial-of-service network-vulnerability vulnerability network-security remote-access
5t 1c
medium advisory

Detection of TeamViewer Desktop Installation

This brief documents the detection of TeamViewer Desktop installation via file system activity, often associated with Remote Access Software usage.

remote-access monitoring
1r
medium advisory

Detection of GoToAssist Remote Support Temporary Artifacts

Adversaries often abuse legitimate remote access software like GoToAssist to establish interactive command-and-control channels, leaving specific temporary artifacts in the user's local profile.

remote-access command-and-control living-off-the-land
1r
high advisory

Threat Actors Impersonate IT Support via Microsoft Teams to Deploy Node.js Implants

Threat actors impersonate IT helpdesk staff in Microsoft Teams to socially engineer users into granting remote access, subsequently deploying a Node.js-based implant for reconnaissance and lateral movement.

Teams +2 social-engineering collaboration-abuse remote-access lateral-movement
1r 2t
high advisory

Improper Client-Side Security Enforcement in tsi-dpdp-cms

The tsi-dpdp-cms software contains a vulnerability in versions 0.5.0 and earlier that improperly relies on client-side enforcement for security controls, allowing for remote exploitation via publicly available exploit code.

tsi-dpdp-cms vulnerability remote-access web-security
1c
rumour rumour

Abuse of Faronics Deploy for Remote Execution and Persistence

Threat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.

Faronics Deploy persistence remote-access execution privilege-escalation
1r 1t updated
medium advisory

Unauthorized VNC Exposure to the Internet

The exposure of VNC services to the public internet enables unauthorized remote access, providing adversaries a vector for initial access or persistent backdoors.

vnc c2 network-security remote-access
1r 2t
high threat

Multiple Vulnerabilities in TeamViewer Client

TeamViewer clients are affected by multiple vulnerabilities that allow an unauthenticated or local attacker to execute arbitrary code with the privileges of the logged-in user.

exploited TeamViewer Client vulnerability remote-access code-execution
1t
high advisory

Veeam ONE Security Bypass Vulnerability

A vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.

PoC Veeam ONE vulnerability remote-access monitoring
1t 1c updated
low advisory

Data Manipulation Vulnerability in Devolutions Remote Desktop Manager

A vulnerability in Devolutions Remote Desktop Manager allows a remote, unauthenticated attacker to manipulate data, leading to unauthorized modification risks.

Remote Desktop Manager vulnerability remote-access
1c
high advisory

Unauthenticated Access Vulnerability in FitSoft POS System

FitSoft POS System contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access and control over the platform.

POS System vulnerability remote-access pos
1t 1c
high advisory

Flooding Dropper npm Supply Chain Campaign

An automated supply chain campaign targeting npm, deploying multi-stage loaders across 850+ malicious packages that utilize DNS TXT fallback for C2 and reflective payload execution.

npm registry supply-chain npm malware persistence evasion remote-access
3t
critical advisory

Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client

A heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.

FreeRDP vulnerability remote-access windows rdp
1c
high advisory

Heap Out-of-Bounds Read in FreeRDP Glyph Caching

FreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.

FreeRDP vulnerability memory-safety remote-access tls man-in-the-middle
1t 1c
high advisory

Shell Command Execution via Elastic Endpoint Console

Attackers who compromise Elastic Endpoint console access can leverage its legitimate remote support feature to execute arbitrary shell commands on Linux endpoints, turning it into a command and control channel for persistence, tool deployment, and data exfiltration.

Elastic Endpoint command-and-control defense-evasion execution linux endpoint-security remote-access
1r 3t
medium advisory

Accepted Default Telnet Port Connection

This threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.

telnet network-security remote-access plain-text initial-access lateral-movement command-and-control
1r 4t
medium threat

Multiple Vulnerabilities in Absolute Secure Access

An attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.

exploited Absolute Secure Access vulnerability denial-of-service information-disclosure remote-access
2t
high advisory

Emerging Threat: QuimaRAT, a Cross-Platform Java-Based Remote Access Trojan

QuimaRAT is a newly identified Java-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) model, capable of targeting Windows, Linux, and macOS systems with a modular architecture for remote access and dynamic functionality expansion.

RAT MaaS Java cross-platform remote-access
2t
high threat

H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)

A critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.

exploited NX15 V100R017 vulnerability api-exploitation password-reset network-device remote-access
2t 1c 5i
high advisory

RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)

An authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.

RustDesk < 1.4.9 vulnerability authorization-bypass remote-access
1t 1c
high advisory

New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.

ClickOnce +2 persistence initial-access defense-evasion remote-access microsoft windows
2r 5t
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
medium advisory

VNC (Virtual Network Computing) to the Internet

This brief details the risk of VNC (Virtual Network Computing) traffic originating from internal networks and destined for the internet, indicating potential unauthorized access or a backdoor, as VNC is frequently exploited by threat actors when exposed externally via specific TCP ports (5800-5810).

command-and-control lateral-movement remote-access network
1r 2t
high advisory

VNC (Virtual Network Computing) from the Internet

This brief detects unauthorized Virtual Network Computing (VNC) traffic originating from the Internet and targeting internal network segments on TCP ports 5800-5810, indicating potential initial access or backdoor exploitation by threat actors leveraging exposed VNC services.

command-and-control initial-access remote-access network vnc
1r 3t
medium advisory

First Time Seen Remote Monitoring and Management Tool Detection

Adversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.

AA +132 command-and-control persistence execution rmm remote-access windows
1r 3t 5i
high advisory

Tiflux RMM Abused in Malspam Campaign

A malspam campaign is leveraging the Tiflux RMM to gain remote access and persistence on victim machines, abusing legitimate remote management software for stealthy access and persistence.

Tiflux +3 remote-access rmm malspam persistence
2r 1t 2i
critical threat

Multiple Vulnerabilities in Oracle Java SE

A remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.

Java SE java vulnerability remote-access
2r 1t
high advisory

Vulnerabilities Disclosed in IP KVM Devices from Multiple Vendors

Researchers have disclosed unspecified vulnerabilities in IP KVM devices from four manufacturers, potentially allowing attackers to gain unauthorized access to connected systems.

ip-kvm vulnerability remote-access
2r 2t
medium advisory

VScode Remote Tunnel Abuse for Command and Control

Adversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.

Visual Studio Code vscode remote-access command-and-control windows
2r 1t
medium advisory

Detection of Suspicious VScode Remote Tunnel Usage

This brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.

Visual Studio Code command-and-control vscode remote-access windows
2r 1t
medium advisory

Remote Management Software Launch After MSI Install

Attackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.

ConnectWise ScreenConnect +3 remote-access rmm msi command-and-control
3r
medium advisory

First Time Seen Remote Monitoring and Management Tool Execution

Detects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.

Elastic Defend +101 remote-access rmm command-and-control persistence
3r
medium advisory

Suspicious Remote File Copy via TeamViewer

Attackers may abuse TeamViewer, a legitimate remote access tool, to transfer malware or tools into a compromised environment by creating executable or script files with suspicious extensions.

TeamViewer command-and-control remote-access
2r 2t
medium advisory

Remote Management Access Launch After MSI Install

Detects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.

ScreenConnect +3 remote-access command-and-control rmm msi
2r
high advisory

Newly Observed ScreenConnect Host Server

Detection of ScreenConnect clients connecting to a newly observed host server outside the official ScreenConnect cloud, potentially indicating command and control activity or compromise.

ScreenConnect remote-access command-and-control windows
2r 1t
medium advisory

Suspicious DNS Queries to RMM Domains from Non-Browser Processes

Detection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.

Elastic Endpoint +1 command-and-control remote-access windows
2r
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t
medium advisory

Remote File Copy via TeamViewer

Attackers may abuse legitimate utilities such as TeamViewer to deploy malware interactively by remotely copying executable or script files during a TeamViewer session.

Elastic Defend +2 command-and-control remote-access teamviewer
2r 2t
medium advisory

Detection of Level RMM Watchdog Task Creation

The creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.

Level remote management tool +3 rmm remote-access persistence
2r 2t