UltraVNC is an open-source remote administration utility for Windows that implements VNC-based remote desktop access. Although it is legitimate software, it is frequently repurposed by threat actors as a remote access tool to obtain interactive control of compromised systems. In intrusion activity, operators have used UltraVNC or UltraVNC Server alongside other malware and administration tooling to maintain hands-on access, execute follow-on actions, and support broader post-compromise operations.
Observed malicious use includes deployment by phishing-driven intrusion sets and supply-chain compromises, as well as installation after initial access by other malware. Reported campaigns have used UltraVNC together with tools such as QuasarRAT, PowerShell-based downloaders, NGROK, keyloggers, and custom backdoors. Threat actors associated with its abuse include Larva-24009, UNC2465, Awaken Likho, and Gamaredon-linked operations. In these contexts, UltraVNC has been used to provide system control over infected Windows hosts, sometimes as an off-the-shelf payload delivered through multi-stage execution chains and sometimes as a renamed component installed after compromise.
Its role in malicious operations is primarily post-exploitation remote control rather than initial compromise. UltraVNC itself is not inherently malware, but when installed covertly by an adversary it functions operationally as a remote access trojan-like capability on victim systems. Reported targeting associated with such abuse includes enterprises, government organizations in Russia and Belarus, Ukrainian entities, and victims reached through compromised software distribution channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В ходе исследования было обнаружено, что бэкдор впервые появился в июле 2025 года, но тогда он устанавливался с помощью UltraVNC, а не собственного ПО TokenBuoy.
В ходе исследования было обнаружено, что бэкдор впервые появился в июле 2025 года, но тогда он устанавливался с помощью UltraVNC, а не собственного ПО TokenBuoy.
The threat actor installed Quasar RAT and UltraVNC Server to achieve System Control over the infected system.
These attachments relied on a multi-stage execution chain, often using up to three nested stages, to download and execute off-the-shelf payloads like Remote Manipulator System (RMS) RAT, a tool widely shared on Russian hacker forums, or UltraVNC, an open-source remote access utility.
“deploying two types of payloads. The first is a manipulated Ultra VNC program…”
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Historically, according to the 2015 LookingGlass report Operation Armageddon: Cyber Espionage as a Strategic Component of Russian Modern Warfare, Gamaredon conducted spearphishing campaigns using stolen, highly relevant decoy documents of mimicking Ukrainian institutions to target government entities.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote administration software previously used by the threat actor during earlier infection stages and to install TokenBuoySH in an earlier campaign.
Remote control software installed on infected hosts to provide screen-based remote access; the actor uses UltraVNC Server on victims and connects via UltraVNC Viewer.
Open-source remote access utility used as an off-the-shelf payload in early Gamaredon intrusion chains.
UltraVNC is a legitimate remote access tool that was abused by the attacker to maintain remote desktop access to compromised systems. It was configured for persistence and used in conjunction with NGROK for external access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.