Security1 distinct publisher3 min readPublished
The joint advisory says the actors never installed the clients. Portable copies ran in the user's context, pointed at attacker-run RMM servers, and installation controls never saw them.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The control that fails here is one most organisations file under "done": software allowlisting plus installation auditing. According to the joint advisory, the actors did not install the downloaded RMM clients on compromised hosts at all. They ran AnyDesk and ScreenConnect as self-contained portable executables, already configured to connect to the actor's own RMM server [4]. A portable executable launches inside the user's context with no installation step and no administrator privilege, so unapproved software can execute even where a risk management control exists to audit or block installing that same software [5]. The advisory's own framing is that this bypasses common software controls and risk management assumptions [5].
The delivery path was built to miss the same inspection points. Help desk themed emails went to federal civilian staff at both personal and government addresses, and they either carried a link to a first-stage domain or simply asked the recipient to call [11]. In mid-June 2022, an employee at a federal civilian executive branch agency got one of the phone-number variants at their government address, rang it, and was talked into visiting myhelpcare[.]online [7]. Visiting the first-stage domain downloaded an executable, which then reached a second-stage domain to pull down the RMM software [12]. The vendor binary never crosses the mail gateway.
The arithmetic on that is worth stating. Earliest observed activity on a federal network was mid-June 2022 [7]; CISA identified the campaign in October 2022, working from trusted third-party reporting and retrospective analysis of EINSTEIN, the intrusion detection system it runs across federal civilian networks [2][6]. That is roughly four months between the first foothold visible in hindsight and the campaign being recognised as a campaign [15]. There was bi-directional traffic between a federal network and myhelpcare[.]cc as late as mid-September 2022 [8], a month before identification.
Retrospection found two networks first, and further EINSTEIN analysis and incident response found related activity on many other federal civilian networks [6][9]. The signal that eventually carried was network telemetry read backwards, not an endpoint verdict at execution time. CISA also links the campaign to typosquatting infrastructure reported by Silent Push that impersonated Amazon, Microsoft, Geek Squad, McAfee, Norton and PayPal [10], which is the same help desk pretext at scale.
The observed monetisation was mundane: a refund scam that moved money out of victim bank accounts [2]. The authoring organisations' assessment is the part defenders should price, which is that the same access can be sold on to other criminal or APT buyers [3], and that criminal and state-sponsored actors alike are known to keep legitimate RMM software in place as a backdoor for persistence or command and control [13]. A live, authenticated remote control session is a better product to resell than a credential dump.
Which leaves the discriminating field. It is not the process name, because the process name is the one your help desk approved. It is which RMM server the client authenticates to [4], and that is not a field most software inventories keep. The advisory points defenders at its own IOC and mitigation sections for the rest [14].
Ranked by verification strength, evidence, and original report placement.
CISA, the NSA and MS-ISAC released a joint Cybersecurity Advisory warning network defenders about the malicious use of legitimate remote monitoring and management (RMM) software.
In October 2022, CISA identified a widespread cyber campaign involving malicious use of legitimate RMM software: criminal actors sent phishing emails leading to the download of ScreenConnect (now ConnectWise Control) and AnyDesk, which they used in a refund scam to steal money from victim bank accounts.
The authoring organizations assess the campaign appears financially motivated but could lead to additional malicious activity, for example the actors selling victim account access to other cyber criminal or advanced persistent threat actors.
CISA noted the actors did not install the downloaded RMM clients on the compromised host; instead they downloaded AnyDesk and ScreenConnect as self-contained, portable executables configured to connect to the actor's RMM server.
Portable executables launch within the user's context without installation and do not require administrator privileges, so they can allow execution of unapproved software even where a risk management control is in place to audit or block installation of the same software, effectively bypassing common software controls and risk management assumptions.
In October 2022 CISA used trusted third-party reporting to conduct retrospective analysis of EINSTEIN, a federal civilian executive branch (FCEB)-wide intrusion detection system operated and monitored by CISA, and identified suspected malicious activity on two FCEB networks.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Strong first-party technical detail, single publisher
The claims rest on a primary joint government advisory with named detection provenance (EINSTEIN retrospective analysis), dated incidents, specific malicious domains, described tradecraft, and machine-readable IOCs. What limits the score is that the cluster contains exactly one source: the only external corroboration mentioned is a Silent Push blog referenced inside the advisory rather than supplied independently, and no victim counts, loss figures or remediation outcomes are given.
Confirmed real-world incidents on federal networks
Adoption here is observed real-world occurrence rather than product uptake, and it is concrete: dated phishing and command-and-control events on two FCEB networks, related activity found on many other FCEB networks, a working refund-scam monetisation path, and a linked brand-impersonation domain operation. It is not higher because 'many other FCEB networks' is unquantified and no private-sector victim scale is provided.
Understated: dry advisory framing for a broad control failure
The advisory's language is conservative and hedged - assessments are labelled as assessments, the escalation scenario is explicitly framed as possibility rather than observation, and no severity superlatives are used. Yet the underlying finding, that legitimate signed remote-access binaries run without installation or admin rights and therefore defeat a widely relied-upon class of software control, is broader than the modest presentation suggests. Slightly negative rather than strongly so, because the cluster does not overreach in either direction.
Institutional, not commercial, incentive
The sole publisher is the agency that operates the detection system it credits and that issues the guidance it asks defenders to adopt, so there is an institutional interest in demonstrating EINSTEIN's value and in driving uptake of its mitigations. Against that, there is no commercial or fundraising incentive, named vendors are third parties described neutrally, and the reporting is hedged and artifact-backed - so the incentive load is real but low.
High-trust source, no independent check
Confidence is high on the technical mechanism and the dated incidents because they come from the investigating authority with IOC artifacts attached, and the internal account is self-consistent. It is held below the top band because the cluster is single-publisher, key scope figures are qualitative ('many other FCEB networks'), and no follow-up on remediation or affected-vendor response is available to cross-check.
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
product
After Arup, a face on a video call is not a credential1 distinct publisher
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026