Remote Utilities is a legitimate commercial remote administration and remote monitoring/management (RMM) tool developed by Remote Utilities LLC that is repeatedly observed being installed by threat actors to obtain interactive control of victim Windows systems. In the provided reporting it is described as a remote access tool/RAT and is also referred to as RuRat. Threat actors use it as a post-compromise access mechanism rather than as a bespoke malware family.
Observed abuse includes installation by the Mexico-focused banking fraud campaign REF6045 as an optional escalation step in higher-value intrusions involving the SCMBANKER toolkit, where operators can silently deploy Remote Utilities for direct hands-on access to victim machines. CERT-UA also reported a phishing campaign tracked as UAC-0096 that spoofed the Apparatus of the National Security and Defense Council of Ukraine and delivered an executable named KB5017371.exe from a RAR attachment; executing the payload installed Remote Utilities on the victim host. CERT-UA further listed Remote Utilities among the malware/tooling used across campaigns attributed to UAC-0050. Additional reporting states Asylum Ambuscade can deploy Remote Utilities through its AHKBOT/NODEBOT plugin ecosystem, and Bitdefender observed the Curly COMrades cluster installing the legitimate RMM tool Remote Utilities as a service named RemUtSvc for additional access.
Installation and artifact details directly mentioned in the content include download of a Remote Utilities component via a path ending in rutserv/agent6.10.exe, the client binary rfusclient.exe, the host service binary rutserv.exe, installation paths under %PROGRAMDATA%\Remote Utilities, %PROGRAMFILES%\Remote Utilities - Host, and %PROGRAMFILES(X86)%\Remote Utilities - Host, registry key HKLM\SOFTWARE\Usoris\Remote Utilities Host, and service names RManService and RemUtSvc. In the UAC-0096 reporting, associated files included host-7.1.7.0_unsigned.msi and multiple hashes for KB5017371.exe, KB5017371(unpacked).exe, rfusclient.exe, and rutserv.exe. High-confidence network indicators from that campaign included IPs 77.91.100.6, 91.228.10.77, 111.90.148.190, 111.90.148.194, 111.90.148.199, 111.90.148.197, 101.99.91.158, 101.99.91.170, 101.99.91.179, 101.99.91.167, 101.99.91.19, 101.99.91.76, 101.99.93.104, and 101.99.93.109, with observed TCP endpoints including ports 5651 and 8080 on several of those hosts.
Across the supplied context, Remote Utilities is associated with phishing-based delivery, operator-assisted fraud, and post-exploitation persistence and remote control against government, financial, and other victim organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has also been observed installing legitimate remote access tools like Remote Utilities (RuRat) and commercial RMM software for interactive control.
...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
"...для проникнення до мережі зловмисники використовували скомпрометовані облікові записи VPN..."
In instances where FIN12 leveraged UNC2053 for initial access, we observed BAZARLOADER payloads distributed via malicious email campaigns.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial remote access software deployed by SCMBANKER operators to gain full hands-on control of victim machines during higher-value fraud cases.
Legitimate remote access/RMM tooling abused for interactive access and control of victim systems.
Legitimate remote administration/RMM software abused to maintain interactive access and persistence (installed as a service) after initial compromise.
Legitimate commercial remote administration tool abused as a RAT to provide full interactive control of compromised hosts; delivered via an AHKBOT plugin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.