Remote Manipulator System (RMS) is a legitimate remote administration product developed by the Russian company TektonIT that threat actors abuse as a remote access tool. It supports remote desktop control and sharing, command execution through terminal access, file transfers, network mapping, webcam and microphone access, encrypted remote desktop connections, and RDP integration. The product supports Windows and Android, while documented malicious deployments primarily involve Windows systems. Connectivity can use developer-hosted Internet-ID services or self-hosted relay infrastructure.
Malicious deployments commonly install attacker-configured RMS through multistage scripts and Windows Installer packages. Distribution methods include spear-phishing emails with weaponized Word or Excel attachments, links to nested archives, and executables disguised as documents. RMS has also been bundled with Ovidiy Stealer in a cryptocurrency-software lure. Observed installations establish persistence through logon autorun entries. Abuse of legitimately signed software and unattended installation helps attackers maintain access while reducing the visibility of their activity.
RMS has been used by TA505, UAC-0050, and other unrelated threat actors. Campaigns have targeted US retailers, food and beverage organizations, financial institutions across several countries, and Ukrainian organizations. UAC-0050 has used RMS alongside other remote access tools to compromise accountants’ computers and conduct fraudulent payments through remote banking systems. RMS has also been deployed against a European financial institution involved in regional development and reconstruction, and as an auxiliary remote access tool in a cryptomining campaign. Its legitimate functionality enables reconnaissance, remote command execution, and data transfer without requiring a purpose-built malicious implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Remote Manipulator System (RMS) is a legitimate remote administration tool developed by a Russian organization ‘TektonIT’ and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors.
These attachments relied on a multi-stage execution chain, often using up to three nested stages, to download and execute off-the-shelf payloads like Remote Manipulator System (RMS) RAT.
This was the first time Proofpoint observed UAC-0050 deliver NetSupport, as it has historically used other malware including Remcos and Lumma Stealer, but it has previously used RMMs including Litemanager and Remote Manipulator System (RMS).
"The execution results in the deployment of an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software that allows remote control, desktop sharing, and file transfers."
1 distinct technique documented for this family, organized by ATT&CK tactic.
Using legitimate tools and settings to persist versus malware implants such as Cobalt Strike is a popular technique among ransomware attackers to avoid detection and remain resident in a network for longer. Some of the common enterprise tools and techniques for persistence that Microsoft has observed being used include: AnyDesk, Atera Remote Management, ngrok.io, Remote Manipulator System, Splashtop, TeamViewer.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Off-the-shelf remote access trojan used in early Gamaredon campaigns delivered through spearphishing attachments.
Legitimate remote administration/remote desktop software deployed by the actor to provide persistent remote control (desktop sharing, file transfer) and evade some traditional AV controls by blending in as a legitimate tool.
A remote management tool previously used by UAC-0050 for remote access operations.
A closed-source remote-administration tool deployed by the campaign to remotely control compromised machines and issue commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.