Atera is a legitimate cloud-based IT management and remote monitoring and management (RMM) platform used by managed service providers. It is not inherently malware, but threat actors abuse unauthorized Atera agents to obtain remote control, execute commands and scripts, install additional software, and maintain persistent access to compromised Windows endpoints and servers. Its legitimate administration functions and trusted software infrastructure allow malicious activity to blend with ordinary IT operations.
Malicious deployments use renamed Windows Installer packages, phishing lures impersonating familiar software or document-sharing services, and loaders that silently install the agent. FIN7 has distributed trojanized legitimate software containing an Atera agent installer, while QakBot has delivered Atera as a follow-on remote-access tool. Attackers have also deployed Atera after exploiting PaperCut vulnerability CVE-2023-27350, FortiClient EMS vulnerability CVE-2023-48788, and CitrixBleed vulnerability CVE-2023-4966. Installing an independent management agent can preserve access after the original vulnerability is patched.
Atera abuse has been associated with LockBit operators, Qilin affiliates, the CSuite phishing operation, Iran-linked TA450, and UAC-0180 campaigns targeting Ukrainian defense enterprises. Observed uses include remote PowerShell execution and deployment of additional remote-access products such as AnyDesk and ScreenConnect to provide redundant access. Atera has also served as a secondary access and persistence mechanism in Everest ransomware intrusions. Its use spans financially motivated and espionage operations; the presence of an authorized Atera installation alone does not establish malicious activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Downloaded .msi files were typically either Atera or ScreenConnect, which could provide adversaries with remote access to affected devices.
“Atera is a legitimate… remote monitoring and management tool… they install their own Atera agents…”
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CSuite utilise Atera parmi les outils de gestion légitimes renommés et déployés via des leurres de phishing.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3.
...завантаження і встановлення MSI-файлу легітимної програми для віддаленого управління ЕОМ ATERA...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
After ‘xp_cmdshell’ was enabled, the threat actor used it to install different remote management and monitoring (RMM) tools... they executed a PowerShell command designed to list all processes associated with the Atera RMM software.
CISA and the FBI included technical advice victims can turn to when investigating Medusa attacks, noting that the hackers use several credential stealing tools before turning to legitimate remote monitoring software to evade detection.
Déploiement d'outils légitimes de gestion ... renommés en Adobe, Dotloop, DocuSign.
Once access is established, BlackSuit has been observed using PsExec, RDP, and Remote Monitoring and Management (RMM) tools, including AnyDesk, LogMeIn, and Atera for lateral movement and persistence.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote-management platform abused by a Qilin affiliate to deploy additional remote-access software.
Outil légitime de gestion et d’accès distant abusé pour établir un accès aux endpoints dans l’opération CSuite.
A cloud-based IT management platform abused through renamed MSI installers. Attackers use its package management and agent functionality to install and manage secondary payloads, notably ScreenConnect.
Remote management and monitoring tool abused by the threat actor as a persistence mechanism after exploitation of FortiClient EMS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.