LogMeIn
LogMeIn is a remote access and support software. Qilin ransomware affiliates used LogMeIn for reconnaissance and remote access during post-exploitation activities after…
LogMeIn is a remote access and support software. Qilin ransomware affiliates used LogMeIn for reconnaissance and remote access during post-exploitation activities after…
RedHook is an Android trojan that has resurfaced with new capabilities including autonomous privilege abuse via Android's Wireless ADB Debugging. It provides…
ConnectWise ScreenConnect is a legitimate remote access software delivered as part of phishing campaigns using The Quarry kit.
VioletRAT is a remote access trojan included in The Quarry PhaaS kit, used for post-compromise access.
Remote Utilities is a commercial remote-access tool that is deployed by the SCMBANKER malware to provide hands-on access to victim machines. It…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
Go2Tunnel is a tool used by Armored Likho for remote access and network tunneling, establishing reverse SSH tunnels to C2 servers. It…
Zoho Assist was used by Storm-2603 as one of multiple remote access channels during ransomware attacks, alongside Cloudflare tunneling and SSH.
Citrix Receiver is a remote access client whose signed binary was abused for DLL sideloading by Mustang Panda.
A remote access trojan delivered as a second-stage payload in the PolinRider campaign. Unpacked from encrypted payloads fetched via blockchain services like…