Threat reporting shows legitimate remote administration and monitoring tools being repeatedly repurposed for intrusion, persistence, and ransomware deployment. Walmart Global Tech highlighted abuse of RemotePC, UltraViewer, MSP360, PDQ Deploy, and Zoho Assist, noting their use for remote control, lateral movement, script execution, phishing-enabled access, and data theft; the report tied UltraViewer to FatalRAT activity and linked Zoho tooling to broader exploitation trends, including CVE-2021-40539 in ManageEngine environments. Separately, KELA documented an initial access broker selling access to 53 organizations through Zoho ManageEngine Desktop Central, with victims spanning multiple countries and sectors, including government entities, and assessed that direct compromise or credential abuse was more likely than a managed service provider breach.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Walmart Global Tech published a threat-intelligence overview describing how actors abuse RemotePC, UltraViewer, MSP360, PDQ Deploy, and Zoho Assist. The report tied these tools to activity including FatalRAT infections, Avos Locker deployment, Luna Moth phishing operations, and prior Zoho ManageEngine exploitation.
The Walmart report cites CVE-2021-34688 and CVE-2021-34687 as recent RemotePC vulnerability reports. These disclosures added to prior concerns about older RemotePC versions exposing users to multiple security risks.
The Walmart report states that threat actors exploited Zoho ManageEngine CVE-2021-40539 against the International Committee of the Red Cross. The intrusion involved unauthenticated code execution, privilege escalation, and exfiltration of registry hives and Active Directory files through web shells.
KELA reported that the actor offered 36 additional accesses for sale in September 2020, bringing the total observed across July and September to 53. The combined asking value for all 53 accesses was assessed at $153,850, with at least 10 already sold.
KELA observed the same actor offering about a dozen unauthorized accesses via Zoho ManageEngine Desktop Central on a Russian-speaking underground forum. The listings were part of a broader campaign to sell access into victim organizations.
KELA noted that Zoho ManageEngine Desktop Central had previously been targeted via CVE-2020-10189, which was reported as exploited to install malware. This established earlier abuse of the product before the later access-sales activity.
Sophos reported that Avos Locker operators modified Safe Mode boot settings so AnyDesk could run, then used PDQ Deploy to push batch scripts that disabled security tools, created an admin account, configured auto-logon, and executed ransomware filelessly. Sophos also investigated a Linux component targeting VMware ESXi by killing virtual machines and encrypting VM files.
In an October 8, 2020 update cited by KELA, Zoho said weak credentials on ManageEngine products were the likely cause of the investigated compromises. Zoho also said it would block future logins using weak credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcemedium.com
Open sourceke-la.com
Open sourcecybersecurity.att.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.