Cybercriminals are increasingly using legitimate remote access tools to bypass security controls, raising new challenges for organizations that depend on the same software for remote administration.
Key Takeaways:
Cybercriminals are increasingly combining phishing attacks with legitimate remote monitoring and management (RMM) software such as AnyDesk to gain persistent access to victims’ devices. Phishing campaigns that incorporate RMM tools surged by 475% during the first nine months of 2026 compared to all of 2025. These attacks have primarily targeted North American financial institutions and commercial banking customers.
According to a new report from Fortra, attackers trick victims through phishing emails, text messages, or phone calls that impersonate banks. Victims are then directed to fake support websites and persuaded to install legitimate remote access software, which allows attackers to control their systems.
RMM tools are legitimate IT administration products, and they can bypass security controls that would normally block malicious software. Once attackers gain remote access, they can monitor user activity, steal credentials, deploy additional malware or ransomware, and potentially sell access to compromised systems to other threat actors.
When AnyDesk restricted direct software downloads originating from abused infrastructure, attackers quickly shifted to alternative hosting services and modified their delivery techniques to continue distributing remote access tools.
It’s recommended that organizations should treat unauthorized RMM software as a security risk, even when the applications themselves are legitimate. Fortra advises maintaining an approved list of authorized remote management tools and blocking installations that fall outside established policies. Financial institutions should also continue educating customers and employees about phishing tactics and fraudulent support interactions.
Security teams should also monitor the broader attack chain, including phishing sites, redirect infrastructure, and software download locations.
However, restricting RMM tools can improve security, but it may also create operational challenges for IT departments that rely on remote administration software for support and device management. Organizations must balance the need for flexibility and remote support against the growing risk that attackers can misuse the same tools to gain trusted access to corporate systems.