PDQ Connect is a legitimate cloud-based remote monitoring and management (RMM) product that provides endpoint software distribution, patch management, inventory, and remote-control functionality. Threat actors have abused attacker-enrolled PDQ Connect installations to obtain and retain remote access to Windows systems while blending into authorized administrative tooling. Observed abuse includes delivery through phishing, social-engineering lures, and fraudulent software-download pages, with installers renamed or themed as common applications and business documents. Once installed, PDQ Connect has been used to deploy additional RMM products and follow-on malware, including PatoRAT, and has been associated with persistence through the legitimate management agent. Reported users of abused PDQ Connect include MuddyWater/TA450, TA558, and cybercriminal clusters targeting trucking and logistics organizations for cargo theft. CSuite has also used the product alongside other legitimate RMM tools against organizations in the United States and Europe. Abuse declined following the vendor's deployment of new signed builds and updates in October 2025, but unauthorized PDQ Connect installations remain a security concern, particularly where RMM use is not centrally authorized or monitored.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
L’opération CSuite déploie « PDQ Connect » parmi des outils de gestion légitimes renommés pour imiter des logiciels connus.
PDQ Connect is a newer, cloud-based RMM that has seen abuse from APT groups like MuddyWater. While it has previously appeared in generalized crimeware, PDQ Connect abuse has largely diminished following the company’s rollout of new signed builds and updates in October 2025.
While the actor favors VenomRAT, TA558 also distributes other commodity malware including njRAT, Remcos RAT, and recently XWorm and PDQ Connect.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
“Legitimate management tools can be abused to gain persistent access to employee devices” and “direct remote control of employee devices.”
SimpleHelp ... is often used in phishing campaigns involving “invitation” lures in which the victim is encouraged to download and execute an invite to a party (e.g. Ecard9140.exe ).
A common lure is themed as a Social Security statement ( ssa.msi ) in an attempt to convince the victim they need to run the file to retrieve their statement.
The initial infection occurs via specially crafted spam messages purporting to be from financial institutions or cell phone carriers with an overdue bill or electronic receipt of payment issued as an NF-e... Both messages link to a Dropbox file, which contains the malicious binary installer for the RMM tool.
Livraison du payload : ... script batch/VBS téléchargeant l'installeur.
Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).
Déploiement d'outils légitimes de gestion ... renommés en Adobe, Dotloop, DocuSign.
However, in some cases, we observed the threat actor installing an additional RMM tool and removing all security tools from the machine a few days after the initial compromise.
Over the last few years, threat actors have flocked to exploit legitimate remote monitoring and management (RMM) tools—blue-chip IT software like ScreenConnect, LogMeIn Resolve, and PDQ Connect—blurring the line between legitimate IT administration and malicious intrusion.
Instead of leveraging them for initial access points to simply drop malware, attackers now use RMMs as 'a unified control hub' for command-and-control (C2) purposes as well as attack path redundancy.
The network traffic these tools create is also disguised as regular traffic, with many tools using communication over HTTPS and connecting to resources which are part of the infrastructure provided by the application provider.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil légitime de gestion à distance détourné pour accéder aux systèmes victimes dans l’opération CSuite.
A cloud-based remote monitoring and management tool abused through signed MSI installers, often delivered with phishing lures. Attackers use it for remote access and as a stepping stone to deploy additional tools, commonly ScreenConnect.
Legitimate RMM tool abused to obtain remote execution/control and to deploy follow-on payloads (notably PatoRAT).
PDQ Connect, a legitimate RMM tool, is being misused by attackers who trick victims into installing it, granting the attackers remote access to the system. This approach allows attackers to bypass many security controls as the tool is trusted and commonly used for IT support.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.