Atera is a legitimate cloud-based remote monitoring and management (RMM) platform used by managed service providers to administer endpoints remotely. Its agent can provide persistent remote administration, interactive command and PowerShell execution, software deployment, and package-management functions on managed Windows systems. Threat actors have repeatedly abused Atera as a living-off-the-land remote-access capability after initial compromise, often installing tenant-specific agents to retain control while blending with authorized IT tooling. Observed abuse includes deployment following exploitation of public-facing vulnerabilities, including CitrixBleed and FortiClient EMS SQL injection; use by ransomware operations including LockBit, Medusa, and activity associated with Everest/BlackByte; and phishing-led delivery by groups including UAC-0180. Atera has also been used in campaigns targeting Ukrainian defense enterprises and in financially motivated phishing operations that disguise RMM installers as common business software. Because Atera is signed and legitimate, its use can reduce the effectiveness of binary reputation controls; its presence should be evaluated against authorized tenant, account, endpoint-management, and installation context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Atera is a legitimate… remote monitoring and management tool… they install their own Atera agents…”
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CSuite utilise Atera parmi les outils de gestion légitimes renommés et déployés via des leurres de phishing.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3.
...завантаження і встановлення MSI-файлу легітимної програми для віддаленого управління ЕОМ ATERA...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
After ‘xp_cmdshell’ was enabled, the threat actor used it to install different remote management and monitoring (RMM) tools... they executed a PowerShell command designed to list all processes associated with the Atera RMM software.
CISA and the FBI included technical advice victims can turn to when investigating Medusa attacks, noting that the hackers use several credential stealing tools before turning to legitimate remote monitoring software to evade detection.
Déploiement d'outils légitimes de gestion ... renommés en Adobe, Dotloop, DocuSign.
Once access is established, BlackSuit has been observed using PsExec, RDP, and Remote Monitoring and Management (RMM) tools, including AnyDesk, LogMeIn, and Atera for lateral movement and persistence.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil légitime de gestion et d’accès distant abusé pour établir un accès aux endpoints dans l’opération CSuite.
A cloud-based IT management platform abused through renamed MSI installers. Attackers use its package management and agent functionality to install and manage secondary payloads, notably ScreenConnect.
Remote management and monitoring tool abused by the threat actor as a persistence mechanism after exploitation of FortiClient EMS.
A legitimate remote monitoring and management tool abused by Iranian threat actors for persistence and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.