Phishing attacks are leveraging RMM tools more than ever
Hybrid phishing-to-RMM campaigns have emerged as a potent method to target North American financial institutions, with a focused interest in business commercial banking accounts. Through the first nine months of 2026, Fortra has recorded 475% more phishing attacks incorporating RMM tools into the phishing attack chain compared to the entire previous year.
Remote monitoring and management, or RMM, tools are legitimate software products that allow administrators or support personnel to remotely access and manage computers. In these campaigns, threat actors combine RMM tools with phishing, smishing, or vishing techniques to maintain control of victim’s computers and accounts long after initially gaining access.
How are RMM tools deployed in these phishing attacks?
These attacks are particularly challenging as the common IT software tools deployed are seen as legitimate by basic system security measures, easily bypassing any guardrails aimed at malicious applications. Attacks likely begin with a call, email, or text warning the victim about serious issues regarding their bank account and directs them to a malicious website that mimics their financial institution. The phishing page centers a “live chat” function for customer support and includes code that determines the type of operating system used to access the webpage. Once the victim clicks to open the live chat, the appropriate version of the RMM software, most commonly AnyDesk, automatically begins to download.
Additional prompting found on phishing page leading to RMM software download.
The threat actor in communication with the victim can then guide them through completing the software installation and request a specific key to connect to the RMM tool. This key gives the threat actor access to the victim’s computer, where they can continuously watch everything occurring on the infiltrated device. Over time, the actor may steal personal information or account credentials, install additional malicious access controls or ransomware, incorporate the system in future malicious campaigns, or just sell access to the system on criminal marketplaces. Linked GitHub repositories found in the mitigation process have provided a clear look at the breadth of malicious software available to the group members perpetrating these attacks.
GitHub repository found containing RMM executables among more malicious software.
Tactics are evolving and shifting targets
The use of this tactic in campaigns targeting US financial institutions was first observed in Q3 2025. Prior to these campaigns, RMM utilization alongside phishing content was primarily observed in attacks imitating IT services and limited campaigns focused on international banking brands. The US-targeted phishing kits observed were comparable to campaigns targeting Canadian banks earlier in 2025. Consistent with trends seen more broadly in the phishing threat landscape, most campaigns were aimed specifically at commercial banking brands.
Activity peaked most notable in Q1 2026 as a distinct cluster of threat actors settled on a simple standardized phishing template with some files attributable to a threat actor named GhostDrainer. Attacks imitated banking customer service pages and prompted victims to download the AnyDesk executable directly from AnyDesk.com. These campaigns predominantly leveraged significant amounts of phishing URLs generated through the free app development platform Firebase. After being notified of this pattern of malicious activity, AnyDesk limited direct download access to traffic from Firebase domains.
Phishing-to-RMM attacks observed, 2025-2026.
This cut off from AnyDesk had a noticeable effect in limiting the rate of new phishing-to-RMM attacks. However, threat actors quickly pivoted to hosting the executable files on external maliciously registered infrastructure and experimented with new free hosting platforms including CloudFlare’s workers.dev. Fortra pursued extended mitigation of external downloads as a means to disrupt entire campaigns through a single connected point on the attack chain. In response, threat actors began obscuring the malicious executable downloads through external files located within an iframe.
Phishing page code obscuring executable download through external redirect.
Renamed AnyDesk executable and redirect located on domain external from initial phish.
Defending Against Phishing-to-RMM Attacks
Fortra is working to mitigate every piece of attack infrastructure used to host phishing pages, software downloads, redirecting links and lures. As campaigns have frequently been aimed at business account holders, organizations need to ensure they are properly scrutinizing software that may in specific cases be a legitimate part of a system administration routine. Maintaining an allowlist for supported RMM tools and blocking unauthorized installations are more critical than ever for safeguarding a controlled environment. Financial institutions can continue efforts to educate account holders to recognize phishing and fake support scams, and become more familiar with how real support representatives may engage with customers.