Hackers Are Using Legitimate Remote-Access Software to Take Control of Computers

Hackers are finding a new way to get into people’s computers, and this time they are hiding behind software that many businesses legitimately use every day. Instead of relying on obviously malicious programs, attackers are tricking people into installing legitimate remote-management software and then using it to take control of their devices.

The campaign, which was detected in July 2026, begins with a simple trick: a convincing email. Victims may receive what appears to be a meeting invitation, a PDF document, a software update, an electronic invitation, or another ordinary business-related message. The goal is to make the recipient believe they need to download and open a file.

Some of the files are made to look like familiar programs such as Zoom or Adobe Acrobat. Others are disguised as invitations, government documents, or other files that someone might reasonably expect to receive. This makes the attack particularly dangerous because the victim may not realize they are doing anything unusual.

Once the victim opens the downloaded file, something unexpected happens behind the scenes. The file installs a legitimate remote-management program called MSP360. This type of software is normally used by IT departments and technology support teams to remotely manage computers, troubleshoot problems, install software, and perform other administrative tasks.

The important distinction is that the software itself is not necessarily malicious. The attackers are abusing a legitimate tool for an unauthorized purpose. In other words, they are essentially using a legitimate set of keys to get into a building they don’t belong in.

The installation may also ask the user for permission to make changes to the computer. This is the familiar Windows message asking whether you want to allow a program to make changes to your device. If the user approves it, the attackers can gain a much stronger foothold on the computer.

Once MSP360 is installed, the attackers don’t stop there. They use it to install another remote-access program called ScreenConnect. This gives them a second way to connect to the computer.

Having two different remote-access programs is useful to an attacker because it provides a backup. If one program is discovered and removed, the other may still give the attacker access. It also makes the activity harder to identify because both programs can have legitimate uses in a business environment.

From there, the attackers can use their remote access to move additional files onto the computer and run them. The activity observed in this campaign included attempts to collect information and gain access to credentials, which could potentially include passwords or other sensitive information.

One of the reasons this type of attack is concerning is that it doesn’t necessarily look like a traditional virus. Security software and IT teams are accustomed to looking for obviously malicious programs, but legitimate remote-management applications can appear completely normal.

Imagine an office where the IT department regularly uses remote-support software. Seeing that software running on an employee’s computer might not immediately raise an alarm. An attacker can take advantage of that familiarity and hide their activity among normal IT operations.

The attackers also used a variety of online services to host the files involved in the campaign. Some of these are ordinary cloud-storage and development services that businesses use every day. This can make the attack harder to block because the services themselves are legitimate.

The campaign also demonstrates why fake software updates and downloads remain such an effective way to target people. A message saying that you need to install an important Zoom update, open a PDF, or view an invitation can seem harmless. But if the file comes from an unexpected source, clicking it can give an attacker access to the computer.

Interestingly, this wasn’t the only approach observed. Another set of attacks used a different legitimate deployment tool instead of MSP360 before installing ScreenConnect. This suggests that the attackers are willing to experiment with different legitimate remote-management programs to achieve the same goal.

For everyday computer users, the lesson is relatively simple: be careful about what you download, even when the file appears to be an update or a familiar business application. If an email asks you to install software, especially when you weren’t expecting it, take a moment to verify where it came from before opening anything.

Businesses have an additional challenge because remote-management software is often necessary for employees and IT teams. Organizations should know which remote-access programs are approved and which computers they are supposed to be installed on. Unexpected installations should be investigated rather than automatically treated as normal IT activity.

The bigger picture is that attackers don’t always need to create new viruses or discover complicated software vulnerabilities. Sometimes, they can accomplish their goals simply by convincing someone to install a legitimate program and then misusing it.

That makes cybersecurity increasingly about more than just blocking malicious software. It also means paying attention to unexpected emails, unusual software installations, and programs that suddenly appear on a computer without a clear business reason.

For users, a healthy dose of skepticism can go a long way. If an email unexpectedly asks you to install Zoom, update a PDF reader, open an invitation, or download a document, don’t assume that the request is legitimate simply because the software being offered is familiar. When in doubt, go directly to the company’s official website or contact your IT department rather than clicking the link in the message.

In this campaign, the attackers weren’t pretending to be using legitimate technology. They were actually using legitimate technology against their victims. And that’s what makes this type of attack particularly difficult to spot.