Infected Systems Controlled Through Remote Administration Tools – Detected by EDR (2)
ID: 740dafeb-da0f-572c-b395-95f125fcba0a
STIX ID: report--740dafeb-da0f-572c-b395-95f125fcba0a
Feed Name: ASEC
Threat Score
This AhnLab ASEC report documents a rise in threat actors deploying legitimate remote administration tools (GotoHTTP, RustDesk, Atera, ConnectWise ScreenConnect) during initial access and lateral movement to bypass anti-malware and maintain persistent control; it details how AhnLab EDR detects execution and installation behaviors for these tools and highlights their observed use by ransomware groups and APTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
