logo

Infected Systems Controlled Through Remote Administration Tools – Detected by EDR (2)

ID: 740dafeb-da0f-572c-b395-95f125fcba0a

STIX ID: report--740dafeb-da0f-572c-b395-95f125fcba0a

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-11-19

Date Updated: 2026-04-26

Author: ATCP

...
...

This AhnLab ASEC report documents a rise in threat actors deploying legitimate remote administration tools (GotoHTTP, RustDesk, Atera, ConnectWise ScreenConnect) during initial access and lateral movement to bypass anti-malware and maintain persistent control; it details how AhnLab EDR detects execution and installation behaviors for these tools and highlights their observed use by ransomware groups and APTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.