Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

Can legitimate remote-support software be used maliciously?

Yes. An offender can misuse genuine remote-support software to control a victim's device while the product operates exactly as designed. Common routes include deceiving the victim into approving a session, abusing an existing installation, compromising a support account or enabling unattended access.

Once connected, the operator may view the screen, control keyboard and mouse input, open financial services, transfer files, install other software or alter security settings. The commercial legitimacy of the product says nothing about the legitimacy of that session.

Access routeGenuine support productThe software and vendor may be entirely legitimate.
AuthorityApproval, account or unattended settingThe key question is how this particular session obtained access.
SessionRemote control beginsScreen, input, files or settings may become available to the operator.
InvestigationWas this session authorised?Join product records to the surrounding call, message, account and device activity.

Put the session in its human context

Preserve the product version, installation details, account or support identifiers, configuration and session logs. File-transfer history, operator notes, chat records and session recordings may provide unusually direct evidence of what the controller could see or change.

Then align those records with the surrounding interaction:

  • calls, messages or websites that prompted the installation;
  • any codes or permissions the victim supplied;
  • screen, process and file activity during the session;
  • payments or account changes made at the same time; and
  • later connections made through unattended-access settings.

This can distinguish a genuine IT appointment from a deceptive support call or a compromised provider account. Where an organisation has a legitimate support supplier, compare the session identifier, operator account and time with its service records rather than assuming all uses of the approved product were authorised.

Approval may itself be evidence of deception

A victim may click allow and actively follow the offender's instructions. That technical consent does not resolve whether access was honestly obtained or legally authorised. Report the interface event and the surrounding representation separately.

Do not imply that the software vendor participated merely because its infrastructure carried the session. Nor should a session account be equated automatically with its named holder. Use service-side and device evidence to test who controlled it and what actions resulted.

Key takeaway

Legitimate remote-support software is dual-use: reconstruct how approval or access was obtained, what the session did, and who controlled it without blaming the product or equating a technical click with informed authority.

Reference: CIM-081Cyber Incidents & Offender Methods