FleetDeck is a legitimate remote monitoring and management platform abused by cybercriminals to obtain unauthorized remote access and persistent control of endpoints. In malicious deployments, its agent functions as a remote-access tool rather than a purpose-built malware implant. Observed campaigns have deployed FleetDeck on Windows and macOS, using legitimate management infrastructure for agent communications. Its use as authorized administrative software can complicate detection and differentiation from malicious activity.
Attackers distribute FleetDeck through phishing emails, deceptive PDF links, HTML landing pages, and executable installers masquerading as account-statement viewers or invitation documents. Platform-aware phishing pages have delivered FleetDeck specifically to macOS visitors. Installers associate agents with an operator's management account through an embedded deployment identifier. An observed Windows installation chain deployed the agent through an MSI package, registered a Windows service, added inbound firewall rules, and configured the service to operate in Safe Mode with Networking. The agent used PowerShell and WMI to collect domain membership, operating-system and hardware details, BIOS identifiers, network configuration, language settings, and external IP information.
FleetDeck has been used by Scattered Spider actors associated with DragonForce ransomware deployment, although this does not establish attribution for other FleetDeck campaigns. It has also appeared among remote-management tools used in attacks against trucking carriers and freight brokers, where unauthorized access supports reconnaissance, persistent control, and cyber-enabled cargo theft. Credential-harvesting utilities deployed after compromise are separate tools, not evidence of a native FleetDeck credential-stealing capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FleetDeck was previously used by the “Scattered Spider” threat actors who distributed the DragonForce ransomware.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Once active, FleetDeck queried the host through PowerShell and WMI.
Useful combinations include... wscript.exe followed by PowerShell and msiexec.exe, or cmd.exe followed by PowerShell and curl.exe.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-management software weaponized through PDF attachment lures and phishing pages. Downloaded installers embed a deployment ID that is supplied during installation to enroll the endpoint under attacker control.
A legitimate RMM agent abused as a malicious remote-access payload. It is delivered through Paperless Post, Adobe, and related social-engineering lures, with multiple distinct agent binaries suggesting separate operator deployment registrations.
A legitimate remote monitoring and management product abused as an unauthorized remote-access channel. In the observed campaign, it was installed through a phishing-led fake document-viewer workflow, established a service, added firewall and SafeBoot persistence changes, performed host discovery via PowerShell and WMI, and enabled remote administration.
A remote access tool delivered in phishing campaigns to macOS victims after device fingerprinting; described as a technically legitimate RAT repurposed for malicious access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.