Atera Agent is a legitimate remote monitoring and management (RMM) tool that has been repeatedly abused by multiple threat actors as a remote access capability, persistence mechanism, and command-and-control channel. Across the provided reporting, it is described as being deployed after initial compromise or delivered directly through phishing as a first-stage payload. Documented capabilities available to operators through the product include remote control, file transfer, and interactive shell execution, which make it useful as an attacker-operated access tool.
The content links Atera Agent to several threat clusters. Microsoft reported a Seashell Blizzard / Sandworm-associated initial-access subgroup tied to Russia’s GRU Unit 74455 using Atera Agent and Splashtop Remote Services for persistence and C2 after exploiting Internet-facing systems, including ConnectWise ScreenConnect and Fortinet FortiClient EMS, and noted retrieval of Atera installers via bitsadmin and curl from legitimate Atera-hosted URLs. Multiple reports describe MuddyWater, assessed as affiliated with Iran’s MOIS, heavily relying on Atera Agent in phishing-led campaigns from late 2023 through 2024, especially against Israel but also against Saudi Arabia, Turkey, Azerbaijan, India, Portugal, and other countries. In those campaigns, Atera Agent was commonly delivered via spearphishing links to installers hosted on legitimate file-sharing or hosting services including Egnyte, Onehub, filetransfer.io, Sync.com, freeupload.store, and Zendesk Chat upload infrastructure. SentinelLABS also reported Black Basta operators using Atera Agent alongside other remote administration tools such as NetSupport Manager, Splashtop, GoToAssist, and SystemBC.
Observed targeting associated with Atera Agent abuse includes governments and sensitive sectors such as energy, oil and gas, telecommunications, shipping, arms manufacturing, airlines, IT, pharmaceuticals, automotive manufacturing, logistics, travel and tourism, employment and immigration agencies, municipalities, media, and small businesses. Cofense additionally reported that Atera Agent was the most common legitimate RAT observed in Portuguese-language phishing campaigns and was frequently distributed through embedded URLs, with campaign themes spoofing Brazilian organizations.
High-confidence indicators and artifacts directly mentioned in the content include references to archives and installers containing Atera Agent, actor use of legitimate Atera-hosted URLs for installer retrieval, and specific suspected MuddyWater Atera Agent samples and lures such as SHA-256 5d7eb6c36d261adeef1a59bde9eb965f5d8d7f56a2e607da913e782167ba6cb6, 14c270cf53a50867e42120250abca863675d37abf39d60689e58288a9e870144, 638c7a4f833dc95dbab5f0a81ef03b7d83704e30b5cdc630702475cc9fff86a2, 9b49d6640f5f0f1d68f649252a96052f1d2e0822feadd7ebe3ab6a3cadd75985, 2722e289767ae391e3c3773b8640a8b9f6eb24c6a9d6e541f29c8765f7a8944b, and ffbe988fd797cbb9a1eedb705cf00ebc8277cdbd9a21b6efb40a8bc22c7a43f0, as well as a suspected Zendesk-hosted ZIP URL used to distribute an Atera installer: https://v2uploads.zopim[.]io/2/u/K/2uKM8Mhn4WHvqm9pjHrjaogyOYub9ouO/892fedae59b274ca24916de33650d318168ce335.zip.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The subgroup then deployed RMM software such as Atera Agent and Splashtop Remote Services. | Since early 2024, the subgroup has expanded its range of access to include targets in the United States and United Kingdom by exploiting vulnerabilities primarily in ConnectWise ScreenConnect (CVE-2024-1709) IT remote management and monitoring software... This was first observed when the subgroup exploited vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788).
Since early 2024, the subgroup has expanded its range of access to include targets in the United States and United Kingdom by exploiting vulnerabilities primarily in... Fortinet FortiClient EMS security software (CVE-2023-48788). Both CVE-2024-1709 and CVE-2023-48788 provided the ability to launch arbitrary commands on a vulnerable server. | The subgroup then deployed RMM software such as Atera Agent and Splashtop Remote Services.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The subgroup then deployed RMM software such as Atera Agent and Splashtop Remote Services.
"Those archives contained installers for various legitimate remote administration tools." ... IOCs list "Archive containing Atera Agent" and "Atera Agent Installer."
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"MuddyWater has frequently used Egnyte subdomains... Upon opening the shared link, recipients can see the name of the purported sender"
Following exploitation, the subgroup used two methods of payload retrieval to install RMM agents on affected servers: Retrieval of Atera Agent installers from legitimate agent endpoints... via Bitsadmin and curl... [and] from actor-controlled virtual private server (VPS) infrastructure.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote monitoring and management (RMM) agent abused by MuddyWater as a first-stage payload to obtain remote control (file transfer, interactive shell/PowerShell) without needing attacker-owned C2 infrastructure, leveraging Atera trial accounts registered with compromised/leaked email credentials.
Legitimate remote management software abused for persistence and command-and-control after exploitation.
Legitimate remote management tool abused as a payload in MuddyWater phishing campaigns to provide remote access/control of victim environments.
A legitimate remote administration tool whose installer is delivered in archives hosted on file-sharing services and abused by MuddyWater for remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.