Remote Manipulator System (RMS), also known as TektonIT RMS, is legitimate remote desktop and remote administration software that has been repeatedly abused by threat actors as an access tool in intrusion and fraud operations. It provides remote control of victim systems, desktop sharing, and file transfer capabilities, making it useful for hands-on-keyboard access after initial compromise. In malicious operations, RMS is commonly deployed as an MSI-based installer or bundled alongside other malware families and remote management tools.
Observed abuse includes multi-stage phishing and archive-based delivery chains in which victims execute disguised attachments or software-lure bundles that ultimately install RMS for remote access. Campaigns have used nested archives, executable files masquerading as documents, and email-delivered attachments to place RMS on Windows systems. It has also appeared in bundled malware packages distributed under software-themed lures.
RMS has been associated with UAC-0050, a Russia-aligned threat cluster also referred to as the DaVinci Group, in operations targeting Ukrainian entities and at least one European financial institution connected to regional development and reconstruction efforts. In these cases, the software was used to obtain persistent remote access to accountants’ and other targeted users’ computers, supporting intelligence collection and financially motivated activity including fraudulent payment operations through remote banking workflows. Reporting also notes historical use of RMS by cybercriminal delivery chains that install off-the-shelf payloads via staged attachment execution.
Because RMS is legitimate signed remote administration software rather than purpose-built malware, its malicious significance lies in operator abuse rather than intrinsic malicious functionality. In adversary hands, it enables post-compromise remote control, file movement, and sustained access while blending with legitimate administrative tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These attachments relied on a multi-stage execution chain, often using up to three nested stages, to download and execute off-the-shelf payloads like Remote Manipulator System (RMS) RAT.
This was the first time Proofpoint observed UAC-0050 deliver NetSupport, as it has historically used other malware including Remcos and Lumma Stealer, but it has previously used RMMs including Litemanager and Remote Manipulator System (RMS).
"The execution results in the deployment of an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software that allows remote control, desktop sharing, and file transfers."
1 distinct technique documented for this family, organized by ATT&CK tactic.
Using legitimate tools and settings to persist versus malware implants such as Cobalt Strike is a popular technique among ransomware attackers to avoid detection and remain resident in a network for longer. Some of the common enterprise tools and techniques for persistence that Microsoft has observed being used include: AnyDesk, Atera Remote Management, ngrok.io, Remote Manipulator System, Splashtop, TeamViewer.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Off-the-shelf remote access trojan used in early Gamaredon campaigns delivered through spearphishing attachments.
Legitimate remote administration/remote desktop software deployed by the actor to provide persistent remote control (desktop sharing, file transfer) and evade some traditional AV controls by blending in as a legitimate tool.
A remote management tool previously used by UAC-0050 for remote access operations.
A remote access tool/RAT bundled alongside Ovidiy Stealer in at least one observed installer lure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.