Remote Utilities, also referred to as RuRat in threat reporting, is legitimate commercial remote administration software developed by Remote Utilities LLC that threat actors abuse for unauthorized access to Windows systems. Malicious deployments provide interactive remote desktop control and can run as Windows services, allowing operators to maintain access after the initial compromise. Its presence alone does not establish malicious activity.
Remote Utilities has been installed through phishing and spearphishing campaigns, including Ukrainian government-themed security-update lures and evacuation-themed attacks associated with UNC2589, also known as Ember Bear. Other observed users include UAC-0096, UAC-0050, Asylum Ambuscade, and Curly COMrades. These deployments span financially motivated activity and cyberespionage, including operations targeting Ukrainian organizations, Georgian government and judicial entities, and the Moldovan energy sector. The SCMBANKER banking-fraud toolkit can also install Remote Utilities on selected victims in Mexico after a ClickFix-based infection, enabling direct operator interaction.
BalkanRAT uses Remote Utilities as its remote-access component in campaigns targeting financial departments and accountants in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina. These deployments use copies signed with attacker-controlled certificates and configure victim-specific connection identifiers for delivery to the attackers. BalkanRAT supplements the software with firewall exceptions, interface hiding, and a userland rootkit that conceals processes. These concealment mechanisms belong to the surrounding malicious toolkit rather than establishing that the legitimate Remote Utilities product is inherently malicious.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware was delivered via phishing email and the Remote Utilities utility was installed upon execution.
The group has also been observed installing legitimate remote access tools like Remote Utilities (RuRat) and commercial RMM software for interactive control.
...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
"...для проникнення до мережі зловмисники використовували скомпрометовані облікові записи VPN..."
In instances where FIN12 leveraged UNC2053 for initial access, we observed BAZARLOADER payloads distributed via malicious email campaigns.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial remote access software deployed by SCMBANKER operators to gain full hands-on control of victim machines during higher-value fraud cases.
Legitimate remote access/RMM tooling abused for interactive access and control of victim systems.
Legitimate remote-administration software explicitly deployed by attackers in a likely UNC2589 evacuation-themed phishing campaign. The reference describes its use to establish persistence by creating a startup service; it does not describe the software itself as inherently malicious.
A legitimate remote desktop product abused by BalkanRAT to provide remote access to compromised systems. The attackers deploy a maliciously configured copy and hide its presence from victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.