SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
CISA, NSA and MS-ISAC: ScreenConnect and AnyDesk ran as portable backdoors on federal networks
The joint advisory says the actors never installed the clients. Portable copies ran in the user's context, pointed at attacker-run RMM servers, and installation controls never saw them.
The Watch · Security desk

What happened
- CISA, the NSA and MS-ISAC issued a joint advisory on malicious use of legitimate remote monitoring and management software.
- Phishing led victims to download ScreenConnect and AnyDesk, which the actors used in a refund scam to take money from bank accounts.
- Retrospective EINSTEIN analysis flagged two federal civilian networks first, then related activity on many others.
Why it matters
- constraint An allowlist keyed to the remote support tool your own help desk uses stops separating approved from unapproved use, because the control watches installation and no installation occurs.
- decision Defenders now have to choose between blocking portable RMM binaries outright and instrumenting which RMM servers their endpoints are allowed to authenticate to.
- precedent With two named commercial products described as backdoor tooling in a federal advisory, RMM sessions become something a SOC is expected to justify rather than assume.
The control that fails here is one most organisations file under "done": software allowlisting plus installation auditing. According to the joint advisory, the actors did not install the downloaded RMM clients on compromised hosts at all. They ran AnyDesk and ScreenConnect as self-contained portable executables, already configured to connect to the actor's own RMM server [4]. A portable executable launches inside the user's context with no installation step and no administrator privilege, so unapproved software can execute even where a risk management control exists to audit or block installing that same software [5]. The advisory's own framing is that this bypasses common software controls and risk management assumptions [5].
The delivery path was built to miss the same inspection points. Help desk themed emails went to federal civilian staff at both personal and government addresses, and they either carried a link to a first-stage domain or simply asked the recipient to call [11]. In mid-June 2022, an employee at a federal civilian executive branch agency got one of the phone-number variants at their government address, rang it, and was talked into visiting myhelpcare[.]online [7]. Visiting the first-stage domain downloaded an executable, which then reached a second-stage domain to pull down the RMM software [12]. The vendor binary never crosses the mail gateway.
The arithmetic on that is worth stating. Earliest observed activity on a federal network was mid-June 2022 [7]; CISA identified the campaign in October 2022, working from trusted third-party reporting and retrospective analysis of EINSTEIN, the intrusion detection system it runs across federal civilian networks [2][6]. That is roughly four months between the first foothold visible in hindsight and the campaign being recognised as a campaign [15]. There was bi-directional traffic between a federal network and myhelpcare[.]cc as late as mid-September 2022 [8], a month before identification.
Retrospection found two networks first, and further EINSTEIN analysis and incident response found related activity on many other federal civilian networks [6][9]. The signal that eventually carried was network telemetry read backwards, not an endpoint verdict at execution time. CISA also links the campaign to typosquatting infrastructure reported by Silent Push that impersonated Amazon, Microsoft, Geek Squad, McAfee, Norton and PayPal [10], which is the same help desk pretext at scale.
The observed monetisation was mundane: a refund scam that moved money out of victim bank accounts [2]. The authoring organisations' assessment is the part defenders should price, which is that the same access can be sold on to other criminal or APT buyers [3], and that criminal and state-sponsored actors alike are known to keep legitimate RMM software in place as a backdoor for persistence or command and control [13]. A live, authenticated remote control session is a better product to resell than a credential dump.
Which leaves the discriminating field. It is not the process name, because the process name is the one your help desk approved. It is which RMM server the client authenticates to [4], and that is not a field most software inventories keep. The advisory points defenders at its own IOC and mitigation sections for the rest [14].
What to watch
- Whether ConnectWise and AnyDesk add server-side restrictions or attestation for portable, pre-configured builds of their clients.
- Whether federal agencies move from binary-level allowlisting to allowlisting permitted RMM destinations, and whether CISA publishes follow-on IOCs for the same infrastructure.
- Whether later reporting shows access from this campaign actually being resold, which is currently an assessment rather than an observation.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence74
- Adoption63
- Hype gap−8
- Incentives32
- Confidence70
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA, the NSA and MS-ISAC released a joint Cybersecurity Advisory warning network defenders about the malicious use of legitimate remote monitoring and management (RMM) software.
- [2]
In October 2022, CISA identified a widespread cyber campaign involving malicious use of legitimate RMM software: criminal actors sent phishing emails leading to the download of ScreenConnect (now ConnectWise Control) and AnyDesk, which they used in a refund scam to steal money from victim bank accounts.
- [3]
The authoring organizations assess the campaign appears financially motivated but could lead to additional malicious activity, for example the actors selling victim account access to other cyber criminal or advanced persistent threat actors.
- [4]
CISA noted the actors did not install the downloaded RMM clients on the compromised host; instead they downloaded AnyDesk and ScreenConnect as self-contained, portable executables configured to connect to the actor's RMM server.
- [5]
Portable executables launch within the user's context without installation and do not require administrator privileges, so they can allow execution of unapproved software even where a risk management control is in place to audit or block installation of the same software, effectively bypassing common software controls and risk management assumptions.
- [6]
In October 2022 CISA used trusted third-party reporting to conduct retrospective analysis of EINSTEIN, a federal civilian executive branch (FCEB)-wide intrusion detection system operated and monitored by CISA, and identified suspected malicious activity on two FCEB networks.
- [7]
In mid-June 2022, malicious actors sent a phishing email containing a phone number to an FCEB employee's government email address; the employee called the number, which led them to visit the malicious domain myhelpcare[.]online.
- [8]
In mid-September 2022 there was bi-directional traffic between an FCEB network and myhelpcare[.]cc.
- [9]
Based on further EINSTEIN analysis and incident response support, CISA identified related activity on many other FCEB networks.
- [10]
The authoring organizations assess the activity is part of a widespread, financially motivated phishing campaign related to malicious typosquatting activity reported by Silent Push in a blog post on a large trojan operation featuring Amazon, Microsoft, Geek Squad, McAfee, Norton and PayPal domains.
- [11]
The authoring organizations assess that since at least June 2022 cyber criminal actors sent help desk-themed phishing emails to FCEB federal staff's personal and government email addresses; the emails either contained a link to a first-stage malicious domain or prompted recipients to call the cybercriminals, who tried to convince them to visit the first-stage domain.
- [12]
Visiting the first-stage malicious domain triggered the download of an executable, which then connected to a second-stage malicious domain from which it downloaded additional RMM software.
- [13]
Malicious cyber actors, from cybercriminals to nation-state sponsored APTs, are known to use legitimate RMM software as a backdoor for persistence and/or command and control after gaining access to a target network via phishing or other techniques.
- [14]
The authoring organizations strongly encourage network defenders to review the Indicators of Compromise and Mitigations sections of the advisory and apply the recommendations.
- [15]
Approximately four months elapsed between the earliest observed activity on an FCEB network (mid-June 2022) and CISA's identification of the campaign (October 2022).
Sources
1 independent publisher whose own reporting we read for this story.
- cisa.govProtecting Against Malicious Use of Remote Monitoring and Management Software | CISA
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- CISAFollow
- National Security AgencyFollow
- Multi-State Information Sharing and Analysis CenterFollow
- ScreenConnect (ConnectWise Control)Follow
- AnyDeskFollow
- EINSTEINFollow
- Silent PushFollow
- AA23-025AFollow
- myhelpcare[.]onlineFollow
- myhelpcare[.]ccFollow