Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

CISA, NSA and MS-ISAC: ScreenConnect and AnyDesk ran as portable backdoors on federal networks

The joint advisory says the actors never installed the clients. Portable copies ran in the user's context, pointed at attacker-run RMM servers, and installation controls never saw them.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying CISA, NSA and MS-ISAC: ScreenConnect and AnyDesk ran as portable backdoors on federal networks
Generated illustration

What happened

  • CISA, the NSA and MS-ISAC issued a joint advisory on malicious use of legitimate remote monitoring and management software.
  • Phishing led victims to download ScreenConnect and AnyDesk, which the actors used in a refund scam to take money from bank accounts.
  • Retrospective EINSTEIN analysis flagged two federal civilian networks first, then related activity on many others.

Why it matters

  • constraint An allowlist keyed to the remote support tool your own help desk uses stops separating approved from unapproved use, because the control watches installation and no installation occurs.
  • decision Defenders now have to choose between blocking portable RMM binaries outright and instrumenting which RMM servers their endpoints are allowed to authenticate to.
  • precedent With two named commercial products described as backdoor tooling in a federal advisory, RMM sessions become something a SOC is expected to justify rather than assume.

The control that fails here is one most organisations file under "done": software allowlisting plus installation auditing. According to the joint advisory, the actors did not install the downloaded RMM clients on compromised hosts at all. They ran AnyDesk and ScreenConnect as self-contained portable executables, already configured to connect to the actor's own RMM server [4]. A portable executable launches inside the user's context with no installation step and no administrator privilege, so unapproved software can execute even where a risk management control exists to audit or block installing that same software [5]. The advisory's own framing is that this bypasses common software controls and risk management assumptions [5].

The delivery path was built to miss the same inspection points. Help desk themed emails went to federal civilian staff at both personal and government addresses, and they either carried a link to a first-stage domain or simply asked the recipient to call [11]. In mid-June 2022, an employee at a federal civilian executive branch agency got one of the phone-number variants at their government address, rang it, and was talked into visiting myhelpcare[.]online [7]. Visiting the first-stage domain downloaded an executable, which then reached a second-stage domain to pull down the RMM software [12]. The vendor binary never crosses the mail gateway.

The arithmetic on that is worth stating. Earliest observed activity on a federal network was mid-June 2022 [7]; CISA identified the campaign in October 2022, working from trusted third-party reporting and retrospective analysis of EINSTEIN, the intrusion detection system it runs across federal civilian networks [2][6]. That is roughly four months between the first foothold visible in hindsight and the campaign being recognised as a campaign [15]. There was bi-directional traffic between a federal network and myhelpcare[.]cc as late as mid-September 2022 [8], a month before identification.

Retrospection found two networks first, and further EINSTEIN analysis and incident response found related activity on many other federal civilian networks [6][9]. The signal that eventually carried was network telemetry read backwards, not an endpoint verdict at execution time. CISA also links the campaign to typosquatting infrastructure reported by Silent Push that impersonated Amazon, Microsoft, Geek Squad, McAfee, Norton and PayPal [10], which is the same help desk pretext at scale.

The observed monetisation was mundane: a refund scam that moved money out of victim bank accounts [2]. The authoring organisations' assessment is the part defenders should price, which is that the same access can be sold on to other criminal or APT buyers [3], and that criminal and state-sponsored actors alike are known to keep legitimate RMM software in place as a backdoor for persistence or command and control [13]. A live, authenticated remote control session is a better product to resell than a credential dump.

Which leaves the discriminating field. It is not the process name, because the process name is the one your help desk approved. It is which RMM server the client authenticates to [4], and that is not a field most software inventories keep. The advisory points defenders at its own IOC and mitigation sections for the rest [14].

What to watch

  • Whether ConnectWise and AnyDesk add server-side restrictions or attestation for portable, pre-configured builds of their clients.
  • Whether federal agencies move from binary-level allowlisting to allowlisting permitted RMM destinations, and whether CISA publishes follow-on IOCs for the same infrastructure.
  • Whether later reporting shows access from this campaign actually being resold, which is currently an assessment rather than an observation.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence74
Adoption63
Hype gap−8
Incentives32
Confidence70
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    CISA, the NSA and MS-ISAC released a joint Cybersecurity Advisory warning network defenders about the malicious use of legitimate remote monitoring and management (RMM) software.

    ReportedSupportedSource: Joint CISA/NSA/MS-ISAC advisoryView cited source
  2. [2]

    In October 2022, CISA identified a widespread cyber campaign involving malicious use of legitimate RMM software: criminal actors sent phishing emails leading to the download of ScreenConnect (now ConnectWise Control) and AnyDesk, which they used in a refund scam to steal money from victim bank accounts.

    ReportedSupportedSource: CISAView cited source
  3. [3]

    The authoring organizations assess the campaign appears financially motivated but could lead to additional malicious activity, for example the actors selling victim account access to other cyber criminal or advanced persistent threat actors.

    ReportedSupportedSource: CISA, NSA and MS-ISAC assessmentView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cisa.gov

    1 article · August 24, 2026

    Protecting Against Malicious Use of Remote Monitoring and Management Software | CISA

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Federal Network DefenseFollow
  • RMM Software AbuseFollow
  • Refund Scam Financial FraudFollow
  • Portable Executable Control BypassFollow
  • Help Desk Phishing and Callback LuresFollow
  • Joint Cyber Advisories and IOCsFollow
Loading related stories