FleetDeck is a legitimate remote monitoring and management (RMM) platform that has been abused by cybercriminals as an unauthorized remote-access payload. Phishing campaigns have delivered FleetDeck agents through deceptive document, invoice, account-statement, invitation, and transportation-themed lures, including platform-aware landing pages that select a macOS payload for compatible victims. On Windows, observed malicious deployments install the FleetDeck agent as a service, add firewall allowances, configure operation in Safe Mode with Networking, collect detailed host and network inventory through PowerShell and WMI, and connect to FleetDeck infrastructure. Cybercriminal clusters have used FleetDeck alongside other RMM products to establish persistent control, conduct reconnaissance, and support follow-on fraud. A cluster targeting trucking and logistics organizations has used FleetDeck and comparable remote-access tools to compromise freight operations and facilitate cargo theft. FleetDeck has also appeared in phishing activity associated with a Nigerian-origin operator, although its use is not exclusive to any single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Once active, FleetDeck queried the host through PowerShell and WMI.
Useful combinations include... wscript.exe followed by PowerShell and msiexec.exe, or cmd.exe followed by PowerShell and curl.exe.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate RMM agent abused as a malicious remote-access payload. It is delivered through Paperless Post, Adobe, and related social-engineering lures, with multiple distinct agent binaries suggesting separate operator deployment registrations.
A legitimate remote monitoring and management product abused as an unauthorized remote-access channel. In the observed campaign, it was installed through a phishing-led fake document-viewer workflow, established a service, added firewall and SafeBoot persistence changes, performed host discovery via PowerShell and WMI, and enabled remote administration.
A remote access tool delivered in phishing campaigns to macOS victims after device fingerprinting; described as a technically legitimate RAT repurposed for malicious access.
Fleetdeck is a legitimate RMM tool used by attackers to gain remote access and control over victim systems in logistics and trucking firms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.