Netskope Threat Labs

RemoteUtilities

ATP Sandbox Adv. Heuristics

RemoteUtilities is a legitimate remote access tool that cyberattackers can abuse to control victim systems without deploying custom malware. Because the vendor signs the software for support workflows, intrusions that install it often bypass detection while operators browse files, run commands, and stage payloads. Defenders should inventory legitimate deployments and alert on unexpected installations or connections to the tool's infrastructure.

First seen
March 2022
Last seen
September 2026

4 techniques across 4 tactics.

TA0005 Stealth

TA0007 Discovery

  • T1083File and Directory Discovery

TA0009 Collection

TA0011 Command and Control

  • T1105Ingress Tool Transfer
Alert Name
Document-PDF.Trojan.RemoteUtilities
Win32.Exploit.RemoteUtilities
Win32.Trojan.RemoteUtilities