Syncro is a legitimate remote monitoring and management (RMM) tool that is increasingly abused by threat actors as a remote-access payload rather than custom malware. It is described as a centralized cloud-based MSP platform used for monitoring and remote support. Reported malicious use includes phishing and fake download pages that trick users into installing the Syncro agent, including invitation-themed lures, fake Microsoft Teams pages, and PDF lures themed as invoices, product orders, or payments that redirect to Google Drive. Red Canary reported that Syncro abuse rose in 2025 as part of a broader trend of adversaries using signed RMM software for file transfer, remote terminal access, script execution, and persistence while blending into normal IT activity.
Observed behavior includes use of signed, self-contained installers and operator-controlled tenant deployments. Red Canary observed SyncroLive.Agent.Runner.exe launching msiexec.exe to sideload additional RMM tools, usually ScreenConnect, and noted that recent Syncro-related ScreenConnect payloads were downloaded from newly registered domains or unusual TLDs such as .online and .top. Syncro commonly communicates with legitimate vendor infrastructure including syncromsp[.]com, syncroapi[.]com, and kabutoservices[.]com. In one Storm-2949 intrusion, the actor established persistence with Syncro/Servably in parallel with ConnectWise ScreenConnect after Microsoft Entra ID account takeover. Two Syncro/Servably MSI wrappers dropped a byte-identical 5.6 MB .NET payload named Kabuto.Installer.Installer.InstallSyncro (SHA-256: e896a9d376bf451092291934cbe06b1cdddb2bc2ecf7f6b6e9af2c6d0d32a816), and the MSI Property table exposed tenant identifiers including API_KEY 7EUjsWCCy0h2yShB_NdJ7w, CUSTOMER_ID 1763306, and FOLDER_ID 4737689, which the analysis assessed as stronger attribution signals than file hashes.
Threat reporting cited in the content associates Syncro abuse with financially motivated intrusions, ransomware precursor activity, Storm-2949, and testing or use by MuddyWater. ASEC also stated that Syncro has been used by threat actors including Chaos, Royal, and MuddyWater. The tool has been observed alongside other abused RMM products such as ScreenConnect, SimpleHelp, NinjaOne, and SuperOps, and in some cases one RMM is used to install another for redundancy and persistence. High-confidence indicators and artifacts directly mentioned in the content include SyncroLive.Agent.Runner.exe, Kabuto.Installer.Installer.InstallSyncro, legitimate Syncro domains syncromsp[.]com, syncroapi[.]com, kabutoservices[.]com, and the Storm-2949 tenant-linked values API_KEY 7EUjsWCCy0h2yShB_NdJ7w, CUSTOMER_ID 1763306, and FOLDER_ID 4737689.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alongside three ScreenConnect MSI siblings ... two Syncro/Servably MSI wrappers ... drop a byte-identical 5.6 MB Kabuto.Installer.Installer.InstallSyncro .NET payload ... MALWARE ... Syncro / Servably, Inc. (legitimate RMM abused via operator-tenant deployment alongside ScreenConnect)
Legitimate remote management tools, including Atera, AnyDesk, Syncro, SimpleHelp, and NetBird, were systematically abused to establish persistent remote access...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
credential-phishing serves as the initial-access vector, with a "technical interview" social-engineering pretext during which the operator drives an MFA-fatigue / SSPR-rotation sequence to seize Microsoft Entra ID accounts.
Instead of relying on malicious software that antivirus tools might catch and flag, they use legitimate remote access tools to blend in with normal IT activity.
SimpleHelp ... is often used in phishing campaigns involving “invitation” lures in which the victim is encouraged to download and execute an invite to a party (e.g. Ecard9140.exe ).
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
credential-phishing serves as the initial-access vector, with a "technical interview" social-engineering pretext during which the operator drives an MFA-fatigue / SSPR-rotation sequence to seize Microsoft Entra ID accounts.
Over the last few years, threat actors have flocked to exploit legitimate remote monitoring and management (RMM) tools—blue-chip IT software like ScreenConnect, LogMeIn Resolve, and PDQ Connect—blurring the line between legitimate IT administration and malicious intrusion.
One of the most striking trends in recent campaigns has been the use of RMM tools as loaders for other RMM tools. Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email. They then use that first tool to push a second, more permanent remote access tool—usually a cracked version of NetSupport Manager or a specially configured ScreenConnect instance.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cloud-based MSP/RMM platform abused via signed, self-contained installers in phishing lures. Attackers use it to establish access and frequently to sideload or install further RMM tools such as ScreenConnect.
A legitimate RMM agent referenced as another remote access tool abused in related social-engineering activity to provide remote access to victim systems.
Legitimate RMM tool delivered via phishing (lures like invoices/orders/payments) to establish remote management/control on victim endpoints; noted as used by multiple threat actors.
Syncro is a legitimate remote access tool used for IT support and device management. In this campaign, attackers use their own signed builds of Syncro to gain unauthorized remote access to victims' machines, enabling full control, remote command execution, file transfer, and theft of sensitive data such as crypto wallet keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.