UltraVNC is an open-source remote administration utility for Microsoft Windows that implements VNC-based remote desktop access. Although it is legitimate software, it is frequently repurposed by threat actors as a remote access tool to obtain interactive control of compromised systems. In intrusion activity, operators have used UltraVNC to establish persistent or on-demand remote desktop sessions, sometimes through repeater infrastructure, and to support hands-on-keyboard post-compromise operations.
Observed malicious use spans multiple threat clusters and campaigns. Gamaredon has deployed UltraVNC in espionage operations targeting Ukrainian entities as part of multi-stage phishing-driven infection chains. Awaken Likho previously used UltraVNC before shifting toward custom backdoors in later campaigns. Larva-24009 installed UltraVNC Server alongside other remote access tooling to control infected enterprise systems. UNC2465, a ransomware-affiliate cluster linked to a software supply-chain compromise, also used UltraVNC for remote access after initial infection.
When abused in attacks, UltraVNC commonly appears as a secondary payload delivered after initial access has already been established through phishing, trojanized installers, or scripted download chains. Its role is typically post-exploitation rather than initial compromise: enabling remote system control, operator interaction, and follow-on activity such as surveillance, credential access, lateral movement, or deployment of additional tools. Because UltraVNC is legitimate administration software, its malicious use often blends with normal remote-management activity and can complicate detection when renamed, reconfigured, or deployed together with other dual-use utilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
deep-green.exe – UltraVNC remote administration tool that connects to a repeater.
В ходе исследования было обнаружено, что бэкдор впервые появился в июле 2025 года, но тогда он устанавливался с помощью UltraVNC, а не собственного ПО TokenBuoy.
В ходе исследования было обнаружено, что бэкдор впервые появился в июле 2025 года, но тогда он устанавливался с помощью UltraVNC, а не собственного ПО TokenBuoy.
The threat actor installed Quasar RAT and UltraVNC Server to achieve System Control over the infected system.
“deploying two types of payloads. The first is a manipulated Ultra VNC program…”
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Historically, according to the 2015 LookingGlass report Operation Armageddon: Cyber Espionage as a Strategic Component of Russian Modern Warfare, Gamaredon conducted spearphishing campaigns using stolen, highly relevant decoy documents of mimicking Ukrainian institutions to target government entities.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote administration software previously used by the threat actor during earlier infection stages and to install TokenBuoySH in an earlier campaign.
Remote control software installed on infected hosts to provide screen-based remote access; the actor uses UltraVNC Server on victims and connects via UltraVNC Viewer.
Open-source remote access utility used as an off-the-shelf payload in early Gamaredon intrusion chains.
A remote administration tool used as one of the payloads in the described Gamaredon intrusion chain, enabling remote access via a repeater.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.