Radmin is a remote administration tool that provides full interactive control of Windows systems. In intrusion reporting, the name can refer either to the legitimate Famatech remote administration product or, in some campaigns, to malware components or attacker-deployed remote access tooling that use the same name. It has been observed in financially motivated operations and broader post-compromise activity as a means of remotely controlling workstations and ATMs, and as part of attacker tool staging alongside tunneling and remote management utilities. In the Stantinko ecosystem, a distinct custom remote administration backdoor was referred to as an Radmin plugin but was explicitly unrelated to the legitimate Famatech product. Across these contexts, the capability consistently associated with Radmin is remote interactive access and post-compromise control of infected or accessed Windows hosts. Because the supplied facts mix legitimate-tool abuse with a separate custom backdoor using the same label, classification as a single malware family is not supportable at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the last several years, it’s become one of the preferred tools for maintaining persistent access to compromised systems. All the hacker needs to do is gain access to the endpoint, change the AnyDesk password or configure a new access profile. This persistence often goes unnoticed for weeks or months.
Windows Application Layer Protocol RMS Radmin Tool Namedpipe ... Application Layer Protocol
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote administration tool referenced as being hosted in the attacker staging location and likely intended for remote access during the intrusion chain that was assessed as a precursor to ransomware deployment.
Legitimate remote administration software abused for remote control of endpoints (including ATMs) during operations.
Custom remote administration backdoor plugin used by Stantinko, unrelated to the legitimate Famatech product despite the name. Supports reconnaissance, file operations, command execution, service control, and exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.