RemoteUtilities is a legitimate remote monitoring and management (RMM) tool that has been abused by threat actors, including Iranian state-linked operators such as MuddyWater, to evade detection and obtain remote access to victim systems. In the provided reporting, RemoteUtilities is listed among RMM tools tested or used by MuddyWater alongside ScreenConnect, Syncro, SimpleHelp, and Atera Agent. Documented capabilities in the content include taking screenshots on a compromised host and using msiexec to install a service. More broadly, the content states that Iranian threat actors have abused legitimate RMM tools such as Atera, Tactical, SimpleHelp, AnyDesk, ScreenConnect, and RemoteUtilities. No specific infection vector, victim sector, or standalone IOC uniquely tied to RemoteUtilities is provided in the content beyond its use as an abused legitimate RMM utility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...tested different RMM tools, from ScreenConnect, Syncro, SimpleHelp, RemoteUtilies..."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote monitoring and management tool abused by Iranian threat actors for persistence and lateral movement.
Legitimate remote administration/RMM tool referenced as one of the RMM products MuddyWater has tested/abused.
Remote administration/RMM tool that can take screenshots (often abused).
Can take screenshots on a compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.