812 set large in orange, above the line: victim devices, run from a single ConnectWise account.
Blog

When Legitimate Tools Become Malware: The Criminal Use of RMM Platforms

Anton Vilenskiy Avatar

Introduction

The abuse of Remote Monitoring and Management (RMM) tools by cybercriminals has been observed for years, primarily in the context of targeted social engineering attacks. In these scenarios, attackers impersonate IT support personnel and persuade victims to install legitimate remote access software, presenting the request as routine maintenance or technical assistance.

This tradecraft has been especially visible in ransomware operations. As documented in Q6 Cyber’s April 2025 report “Calling the Shots – How Ransomware Groups Use Social Engineering for Initial Access,” phone-based social engineering has become a reliable and scalable initial access vector, often replacing or supplementing traditional phishing campaigns. During these interactions, tools such as ScreenConnect, AnyDesk, or built-in utilities like Microsoft Quick Assist are introduced to gain interactive access to victim environments without deploying conventional malware.

Historically, RMM abuse has been viewed as a supporting mechanism rather than a primary payload – an initial foothold used to enable ransomware deployment, data exfiltration, or extortion. This framing, however, no longer reflects how these tools are being used in practice. Increasingly, RMM platforms themselves are serving as the core capability, fulfilling roles traditionally associated with banking trojans, botnets, and remote access trojans (RATs).

This report examines that evolution. It explores how threat actors are moving beyond high-touch, victim-specific intrusions and deploying RMM tools at scale through phishing campaigns, malicious downloads, and automated distribution chains. Used not merely for access but as operational tooling for financial fraud, RMM platforms are reshaping what malware looks like in modern banking and fraud ecosystems and further blurring the line between legitimate enterprise software and criminal infrastructure.

What RMM Tools Are and Why Cybercriminals Use Them

Remote Monitoring and Management (RMM) tools are legitimate IT administration platforms used by organizations and managed service providers to remotely access endpoints, perform maintenance, deploy updates, and troubleshoot issues. These tools provide persistent remote control and are designed to operate continuously as part of normal enterprise workflows.

For cybercriminals, this legitimacy is the core advantage. RMM software is digitally signed, widely deployed, and commonly permitted by endpoint security controls, allowing malicious use to blend into normal administrative activity. Users are also far less likely to question the presence of remote access tools, particularly when framed as IT support or routine maintenance, than unknown executables or phishing attachments. Once installed, RMM platforms offer stable, long-term access while avoiding many of the detection and operational challenges associated with traditional malware, making them especially effective in environments with mature endpoint defenses.

From Targeted Access to Scale

Recent activity should also be viewed against a broader trend observed in the malware ecosystem. As outlined in Q6 Cyber’s September 2025 report “Malware Reloaded: New Players, Old Tactics, Bigger Threats”, threat actors are gradually shifting away from short-lived infostealers toward tooling that provides persistent, interactive access to infected systems. In the current threat landscape, credential theft alone is often insufficient to reliably access financial accounts, particularly as stronger authentication mechanisms such as passkeys gain wider adoption.

Against this backdrop, threat actors are increasingly moving beyond one-off social engineering attacks and integrating RMM tools into repeatable, scalable operations aligned with financial fraud objectives. The following section examines this evolution through observed threat actor tactics, techniques, and procedures (TTPs), highlighting how RMM tools are being operationalized at scale.

One of the clearest indicators of this shift is how RMM tools are now being delivered. Rather than being introduced through carefully tailored, victim-specific social engineering calls, these tools are increasingly deployed through broad, indiscriminate distribution mechanisms. As a result, RMM platforms are being used in a manner that closely resembles botnet-style operations, with large numbers of compromised devices centrally managed through a single RMM administrative account


Picture 2- art 3.pngA ConnectWise admin panel operated by a threat actor with a total of 812 controlled devices.
For distribution, threat actors rely on delivery methods long associated with mass-scale malware campaigns. RMM installers are propagated through large-scale spam operations, malvertising, and traffic originating from compromised websites, including WordPress-based infrastructure. In some cases, actors bypass distribution entirely by purchasing installs directly from traffic vendors, effectively outsourcing the initial infection phase.

Picture 3 - art 3.png

A threat actor distributes an RMM installation file via OneDrive, as these installers are typically larger than traditional malware payloads.
One notable difference between RMM distribution campaigns and traditional malware campaigns is the size of the payload. Because RMM tools are legitimate commercial software, their installation packages are typically much larger than malicious executables or scripts. As a result, threat actors often rely on cloud storage services, such as AWS-hosted object storage or Backblaze, or other file-sharing platforms to deliver these installers, rather than embedding them directly in emails or exploit chains.

Picture 4 - art 3.png

A threat actor distributes an RMM installation file via OneDrive, as these installers are typically larger than traditional malware payloads.

Another prominent RMM distribution method observed is the use of ClickFix attacks. In this approach, victims are shown a fake “Verify you are human” (CAPTCHA) or “fix error” popup on a website, which instructs them to copy a command to their clipboard and execute it via the Windows Run dialog (Win+R). Framed as a routine troubleshooting step, this technique avoids exploit-based delivery while leading the victim to directly install an RMM tool.

When RMM Tools Become Banking Malware

Beyond ransomware activity, recent observations show RMM tools being used directly in financial fraud operations. In these cases, access is maintained not to deploy additional payloads, but to actively facilitate financial fraud through real-time interaction with victim systems.

In these campaigns, attackers often begin by reviewing credentials saved in the victim’s browser to quickly identify accessible banking, payment, and financial services. This initial reconnaissance allows them to assess the value of the compromised system and prioritize targets based on potential return.

Picture5 - art 3.png

An actor is viewing the victim’s saved passwords via ScreenConnect RMM tool.

While direct access to banking platforms remains a primary objective, attackers rarely limit their activity to a single high-value target. Instead, once access is established, they often expand their focus to additional financial and payment-related services available on the compromised system.

Picture 6 - art 3.png

A threat actor labels devices under their control in the ConnectWise RMM panel based on the financial institution targeted.

Picture 7 - art 3.png

An actor purchased an Apple Gift Card and immediately redeemed it from the victim’s device via SimpleHelp RMM tool.
One commonly observed tactic involves the purchase of gift cards using payment details accessible on the compromised system. Attackers leverage saved card information or authenticated sessions to acquire gift cards from major retailers, which can then be quickly resold or redeemed.

Picture 8 - art 3.png

An actor is viewing a txt file with the victim’s crypto wallet key and seed phrase via NetSupport RMM tool.

Attackers also actively search for cryptocurrency wallets stored on or accessible from the victim’s device. This includes browser-based wallets, desktop wallet applications, and saved credentials or recovery phrases.

Picture 9 - art 3.png

A threat actor accesses and controls payment cards associated with a victim’s Amazon account

Beyond personal finance, actors frequently target e-commerce and merchant platforms associated with the victim. Access to seller dashboards or business accounts can enable fraudulent purchases, manipulation of payout settings, or abuse of stored payment methods.

Conclusion and Recommendations

The observed use of RMM tools marks a clear evolution in how financial fraud is conducted. What were once auxiliary access utilities are now being operated as primary tooling for large-scale fraud, mirroring the behavior and objectives of traditional banking malware. Unlike conventional trojans or botnets, however, RMM platforms operate within the bounds of legitimate software, making detection significantly more complex and blurring the distinction between authorized administrative activity and malicious control.

This shift presents a structural challenge for defenders. Traditional anti-malware strategies focused on detecting malicious binaries, exploit chains, or command-and-control infrastructure are often insufficient when the “payload” is a widely trusted commercial product. As threat actors increasingly favor persistent, interactive access over one-time credential theft, financial institutions must adapt controls to address real-time abuse of legitimate remote administration tools.

Recommendations

Consider Stronger Default Application Firewall Settings: Organizations should review and tighten default application firewall and outbound traffic policies to better control the installation and operation of remote administration tools. This includes restricting unauthorized remote access software, limiting outbound connections to unapproved cloud storage or file-sharing services commonly used to host RMM installers, and enforcing stricter egress filtering to reduce the risk of unmanaged remote control sessions.

Enhance Awareness of Remote Access Abuse: Educate employees and customers about ClickFix-style attacks and fake CAPTCHA prompts, clearly communicate that IT will not request copy-paste execution via Win+R, and promote verification of remote support interactions through official channels.