News
Phishing Attacks Using Remote Management Tools Surge, Report Finds
- By Sean Parker
- October 09, 2026
Cybersecurity company Fortra reported on October 8 that phishing attacks involving remote monitoring and management (RMM) tools increased by 475 percent during the first nine months of 2026 compared to the previous year.
The findings, published by Fortra Intelligence and Research Experts (FIRE), highlight a growing problem for IT security teams: attackers don't necessarily need malicious software to take control of a device. Instead, they're exploiting legitimate remote access tools commonly used by administrators and technical support teams.
The campaigns have primarily targeted North American financial institutions, particularly commercial banking customers.
Attackers use fake support interactions to persuade victims to install remote access software, most commonly AnyDesk.
How the Attacks Work
According to the cybersecurity and software company, the attacks typically begin with a phone call, email or text message warning victims about a serious problem with their bank accounts.
Victims are directed to a fraudulent website designed to resemble their financial institution. The page features what appears to be a live customer support chat, creating the impression that help is available.
Behind the scenes, the phishing site identifies the visitor's operating system. When the victim opens the chat, the appropriate version of a remote management tool, typically AnyDesk, begins downloading automatically.
The attacker then guides the victim through installation and asks for the connection key needed to access the computer. Once connected, the criminal can monitor activity on the compromised device.
The security vendor warned that attackers may also steal account credentials and personal information, install additional malware or ransomware, or use the system in future attacks.
Criminal marketplaces can also sell access to compromised computers.
The approach is particularly difficult to detect because the software itself is legitimate. Basic security controls designed to identify malicious applications may not recognize that a trusted administration tool is being used by an unauthorized person.
Attackers Adapt as Defenses Improve
Fortra researchers first observed these campaigns targeting U.S. financial institutions during the third quarter of 2025. Similar techniques had previously appeared in attacks against Canadian banks and campaigns impersonating IT support services.
Activity increased significantly in the first quarter of 2026, when attackers began using standardized phishing pages that impersonated banking customer support.
Some campaign files were linked to a threat actor identified as GhostDrainer.
The attacks frequently relied on phishing URLs generated through Google's Firebase application development platform. Those pages directed victims to download legitimate AnyDesk executables from the company's website.
After being notified about the abuse, AnyDesk restricted direct downloads originating from Firebase domains.
The cybersecurity company said the change reduced the rate of new attacks, but the criminals quickly adjusted their methods.
Attackers began hosting executable files on externally registered infrastructure and experimenting with other free hosting services, including Cloudflare's workers.dev platform.
Some also concealed download redirects within embedded webpage elements, making the malicious delivery process harder to identify.
These changes show how quickly phishing operators can adapt when a particular delivery method is disrupted.
What IT Teams Should Watch For
The findings raise concerns for organizations that rely on remote management tools for everyday IT operations.
Software such as AnyDesk can provide legitimate support personnel with access to computers, but those same capabilities become dangerous when attackers persuade users to grant unauthorized connections.
The cybersecurity vendor recommends maintaining an allowlist of approved RMM tools and blocking unauthorized software installations.
The company also urged financial institutions to educate customers about fraudulent support interactions and explain how legitimate representatives communicate with account holders.
For administrators, the larger concern is that an attack may not end when a phishing page is taken down or a compromised password is changed. If an attacker has already established remote access to a computer, that access may remain available.