Remote Manipulator System (RMS) is a legitimate remote-administration and remote-desktop product developed by TektonIT that has been repeatedly abused as a remote access trojan in Windows intrusions. It supports remote control of endpoints, command execution, desktop sharing, and file transfers. Threat actors have deployed RMS through multi-stage phishing and software-lure infection chains, including password-protected archives and executables masquerading as documents. UAC-0050, also known as DaVinci Group and Mercenary Akula, has used RMS to obtain and maintain unauthorized access to accountants' systems and other Ukrainian and European financial-sector targets, including in operations involving fraudulent remote-banking payments. RMS has also appeared alongside commodity stealers and cryptomining tooling. Its use as signed, commercially available remote-management software can reduce user suspicion and complicate detection relative to bespoke malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These attachments relied on a multi-stage execution chain, often using up to three nested stages, to download and execute off-the-shelf payloads like Remote Manipulator System (RMS) RAT.
This was the first time Proofpoint observed UAC-0050 deliver NetSupport, as it has historically used other malware including Remcos and Lumma Stealer, but it has previously used RMMs including Litemanager and Remote Manipulator System (RMS).
"The execution results in the deployment of an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software that allows remote control, desktop sharing, and file transfers."
1 distinct technique documented for this family, organized by ATT&CK tactic.
Using legitimate tools and settings to persist versus malware implants such as Cobalt Strike is a popular technique among ransomware attackers to avoid detection and remain resident in a network for longer. Some of the common enterprise tools and techniques for persistence that Microsoft has observed being used include: AnyDesk, Atera Remote Management, ngrok.io, Remote Manipulator System, Splashtop, TeamViewer.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Off-the-shelf remote access trojan used in early Gamaredon campaigns delivered through spearphishing attachments.
Legitimate remote administration/remote desktop software deployed by the actor to provide persistent remote control (desktop sharing, file transfer) and evade some traditional AV controls by blending in as a legitimate tool.
A remote management tool previously used by UAC-0050 for remote access operations.
A closed-source remote-administration tool deployed by the campaign to remotely control compromised machines and issue commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.