Skip to content
CIM-081 Cyber Incidents & Offender Methods

Can legitimate remote-support software be used maliciously?

Yes. Legitimate remote-support software can be used by offenders to obtain or maintain control of a device.

Avoid the dangerous assumption

The dangerous assumption is that trusted or commercially available software cannot be part of an attack.

It can.

An offender may persuade the victim to install the tool, abuse an existing installation, compromise the support account or use unattended-access settings.

The software may then be used to:

  • view the screen
  • control the keyboard and mouse
  • open online banking
  • transfer files
  • install malware
  • disable security controls
  • read messages
  • maintain access after the initial contact.

Investigators should preserve:

  • the product name and version
  • installation time
  • support or account identifiers
  • session logs
  • source connection details
  • file-transfer records
  • configuration
  • unattended-access settings
  • chat or call records
  • subsequent device and account activity.

Do not assume the vendor itself was involved. The product may have been functioning exactly as designed while being misused by an offender.

Likewise, do not assume that every support session was malicious. Organisations may have genuine IT providers using the same software.

Compare session timing with calls, messages, payments, user reports and other device events.

The victim may have actively approved the session because they were deceived. Approval does not necessarily make the access legitimate.

A legitimate tool may leave clearer records than custom malware, but those records still require interpretation.

Where the tool supports session recording or operator notes, preserve them promptly. They may show what the controller viewed or changed, but they should still be tested against device and account records.

Operational takeaway

Treat remote-support software as dual-use, preserve the session and account records and assess whether the access was authorised, deceptive or compromised.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.