Syncro is a legitimate, cloud-managed remote monitoring and management (RMM) platform for managed service providers and corporate IT teams. Threat actors abuse its signed agents to obtain remote access to Windows endpoints, maintain persistence, execute commands, and deploy additional software. These deployments use attacker-controlled service accounts or tenants rather than an inherently malicious Syncro codebase. Legitimate signatures and vendor infrastructure can help unauthorized installations blend into normal administrative activity and evade security controls.
Malicious distribution includes invitation-themed phishing, invoice and payment PDF lures linking to hosted installers, and counterfeit Microsoft Teams pages. Installers have also been disguised as Adobe, DocuSign, or Dotloop software. Observed installations include signed, self-contained packages and MSI wrappers configured with operator-specific tenant identifiers. Attackers have used an installed Syncro agent to launch Windows Installer and deploy additional RMM tools, particularly ConnectWise ScreenConnect, providing redundant remote access.
Syncro abuse has been associated with MuddyWater, Chaos, Royal, CSuite, and Storm-2949. Storm-2949 deployed Syncro alongside ScreenConnect for endpoint persistence after Microsoft Entra ID account takeover. CSuite included Syncro among the legitimate management tools delivered in phishing operations targeting organizations in the United States and Europe. Credential theft and cloud-control-plane abuse conducted in these broader operations are distinct from Syncro's own functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CSuite déploie Syncro parmi les outils de gestion légitimes renommés en Adobe, Dotloop ou DocuSign.
Alongside three ScreenConnect MSI siblings ... two Syncro/Servably MSI wrappers ... drop a byte-identical 5.6 MB Kabuto.Installer.Installer.InstallSyncro .NET payload ... MALWARE ... Syncro / Servably, Inc. (legitimate RMM abused via operator-tenant deployment alongside ScreenConnect)
Legitimate remote management tools, including Atera, AnyDesk, Syncro, SimpleHelp, and NetBird, were systematically abused to establish persistent remote access...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
credential-phishing serves as the initial-access vector, with a "technical interview" social-engineering pretext during which the operator drives an MFA-fatigue / SSPR-rotation sequence to seize Microsoft Entra ID accounts.
“Legitimate management tools can be abused to gain persistent access to employee devices” and “direct remote control of employee devices.”
SimpleHelp ... is often used in phishing campaigns involving “invitation” lures in which the victim is encouraged to download and execute an invite to a party (e.g. Ecard9140.exe ).
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).
Déploiement d'outils légitimes de gestion ... renommés en Adobe, Dotloop, DocuSign.
Adversaries frequently sign up for a free trial of a legitimate service (like LogMeIn Resolve or Syncro) using a throwaway email.
credential-phishing serves as the initial-access vector, with a "technical interview" social-engineering pretext during which the operator drives an MFA-fatigue / SSPR-rotation sequence to seize Microsoft Entra ID accounts.
Over the last few years, threat actors have flocked to exploit legitimate remote monitoring and management (RMM) tools—blue-chip IT software like ScreenConnect, LogMeIn Resolve, and PDQ Connect—blurring the line between legitimate IT administration and malicious intrusion.
Les scripts batch/VBS téléchargent l'installeur, et le compte GitHub Ivan3900 héberge les installateurs ScreenConnect.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-management software mentioned as having been weaponized in previously reported phishing or video-file distribution attacks. No Syncro-specific technical details are provided.
Outil légitime de gestion à distance utilisé abusivement comme mécanisme d’accès distant dans la campagne CSuite.
A cloud-based MSP/RMM platform abused via signed, self-contained installers in phishing lures. Attackers use it to establish access and frequently to sideload or install further RMM tools such as ScreenConnect.
A legitimate RMM agent referenced as another remote access tool abused in related social-engineering activity to provide remote access to victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.