• bitcoinBitcoin(BTC)$81,467.00-2.30%
  • ethereumEthereum(ETH)$2,447.10-4.49%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$727.15-5.81%
  • rippleXRP(XRP)$1.36-4.56%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$108.02-6.95%
  • tronTRON(TRX)$0.333036-0.64%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.67%
  • zcashZcash(ZEC)$1,150.22-13.15%
  • HyperliquidHyperliquid(HYPE)$83.73-4.74%
  • dogecoinDogecoin(DOGE)$0.083023-6.23%
  • USDSUSDS(USDS)$1.000.00%
  • moneroMonero(XMR)$522.79-5.35%
  • whitebitWhiteBIT Coin(WBT)$80.05-3.46%
  • chainlinkChainlink(LINK)$12.39-7.39%
  • cardanoCardano(ADA)$0.228946-10.80%
  • leo-tokenLEO Token(LEO)$8.900.24%
  • RainRain(RAIN)$0.010216-6.81%
  • stellarStellar(XLM)$0.189827-4.79%
  • nearNEAR Protocol(NEAR)$4.52-14.19%
  • bitcoin-cashBitcoin Cash(BCH)$279.69-6.96%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • litecoinLitecoin(LTC)$62.19-5.83%
  • CantonCanton(CC)$0.116766-2.49%
  • daiDai(DAI)$1.000.01%
  • uniswapUniswap(UNI)$7.20-6.87%
  • avalanche-2Avalanche(AVAX)$10.00-10.93%
  • USD1USD1(USD1)$1.00-0.01%
  • suiSui(SUI)$1.03-8.50%
  • hedera-hashgraphHedera(HBAR)$0.091533-0.96%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.38-3.35%
  • BitwayBitway(BTW)$1.397.96%
  • quant-networkQuant(QNT)$235.77-6.65%
  • tether-goldTether Gold(XAUT)$4,123.120.33%
  • Global DollarGlobal Dollar(USDG)$1.000.01%
  • shiba-inuShiba Inu(SHIB)$0.000005-3.47%
  • BittensorBittensor(TAO)$267.45-7.24%
  • crypto-com-chainCronos(CRO)$0.059408-5.88%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • EthenaEthena(ENA)$0.202978-9.79%
  • okbOKB(OKB)$123.61-6.42%
  • Pump.funPump.fun(PUMP)$0.005515-12.63%
  • aaveAave(AAVE)$164.38-4.52%
  • Ripple USDRipple USD(RLUSD)$1.00-0.01%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • MemeCoreMemeCore(M)$1.040.91%
  • OndoOndo(ONDO)$0.4868214.23%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.150.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Fortra Reports 475% Rise in Phishing Attacks Abusing Remote-Management Tools – Unite.AI

October 8, 2026
in AI & Technology
Reading Time: 5 mins read
A A
Fortra Reports 475% Rise in Phishing Attacks Abusing Remote-Management Tools – Unite.AI
ShareShareShareShareShare

The most dangerous part of a fake bank-support conversation may be the moment it appears to become helpful. A customer worried about an account problem accepts an offer of assistance, opens a remote-access tool, and gives someone else control of the computer used for banking. The software can be genuine. The person operating it is not.

YOU MAY ALSO LIKE

Anthropic Updates Usage Policy, Adding Model Abuse and Deception Rules – Unite.AI

Apple Is Set To Show Off New Smart Home Devices At An October 13 Event

New research from Fortra, published October 8, reports a sharp increase in phishing campaigns that incorporate remote monitoring and management tools, commonly called RMM. Through the first nine months of 2026, the company recorded 475% more such attacks than during all of 2025, with North American financial institutions and commercial banking accounts a particular focus.

The finding highlights a problem that malware detection alone cannot solve: attackers can persuade people to authorize a legitimate capability for a fraudulent purpose.

What the 475% figure tells us

Fortra’s comparison is between January–September 2026 and the entire preceding year. A 475% increase means the observed count was 5.75 times the baseline, not 4.75 times. Because the periods differ in length, the result should not be described as a conventional same-period year-over-year comparison.

It is also a measure of attacks observed by Fortra, not a census of all global phishing activity, confirmed compromises, or financial losses. The percentage is striking, but it does not establish how frequently a victim granted access or how much money was stolen. Those distinctions matter when translating threat-research findings into business risk.

When a phishing page becomes a remote-control session

Fortra describes fraudulent bank-support pages whose chat prompts lead to a download of remote-access software, commonly AnyDesk. The attacker then guides the victim into granting access. The company reports that campaigns adapted after restrictions on downloads linked from Firebase, shifting delivery to other infrastructure. Its researchers describe efforts to disrupt several parts of the chain, rather than only the initial phishing page.

That progression changes the nature of the threat. A fake login page attempts to obtain information from a person. A remote-control session can put an operator alongside that person while they use applications and accounts. The boundary being crossed is control of the endpoint, with potential consequences beyond one password.

There is no need to assume that the remote-access product has been compromised for this scenario to work. The abuse comes from deception about who is requesting access and why. A recognizable application name can actually reinforce the victim’s belief that the process is legitimate.

For an organization, this creates two separate verification tasks: determining whether a tool is approved and determining whether this particular session is authorized. Passing the first test cannot answer the second.

An established technique with a renewed banking focus

The broader technique predates this report. In a January 2023 joint advisory, CISA, NSA, and MS-ISAC described a phishing campaign abusing legitimate AnyDesk and ScreenConnect software in refund scams. The agencies also warned that remote-management access could support persistence or be sold to other attackers.

A particularly important technical detail was the use of portable executables. The advisory explained that these can run in a user’s context without full installation or administrator privileges. Consequently, a policy that blocks installation may leave a gap if it does not also control execution.

This is why removing local administrator rights is valuable but cannot be treated as a complete answer to remote-access abuse. Defenders need to understand which applications can actually run, how they connect, and what their users have permitted them to do.

The history also puts Fortra’s increase in perspective. Its report is evidence of rising observed use of an established approach, rather than the discovery of a wholly new class of attack. The challenge is that a familiar technique remains effective when a convincing support story meets weak authorization controls.

Trust the session, not just the application name

AnyDesk’s own abuse-prevention guidance warns that criminals misuse remote-access software to steal information, access codes, and money. It advises against giving unfamiliar people device access or sharing banking credentials, and identifies unexpected offers of technical help as a warning sign.

The practical lesson is to establish a support request through an independently trusted channel. If an incoming message claims a banking emergency, contacting the institution through its established app or a known number avoids relying on the contact details supplied by the person raising the alarm.

For employees, the same principle applies to internal support. An urgent request should be verifiable against the organization’s normal process. Training is stronger when it specifies what legitimate support looks like and how to check it, rather than simply asking people to detect suspicious wording.

AnyDesk also documents security controls including custom client policies, two-factor authentication for unattended access, and access-control lists that restrict incoming sessions to authorized IDs or aliases. These controls illustrate that remote access can be constrained beyond merely allowing the executable.

Configuration still needs to match the threat. Strong protection for a company-managed client does not automatically govern a separate copy launched outside the approved support workflow. Nor does authentication of a remote-access account prove that the operator’s request is legitimate.

What defenders should change

CISA’s advisory recommends auditing remote-access tools, reviewing execution logs, and applying application controls to unauthorized software—including portable versions. That is a useful starting point for organizations evaluating this trend.

The operational goal should be a remote-support process that can answer three questions:

  • Which tool is authorized? Maintain an inventory of approved software and enforce execution rules, rather than relying only on installation records.
  • Who can connect? Constrain approved clients and accounts, and make exceptions visible to the team responsible for them.
  • Why is this session happening? Connect remote support to a verifiable request and review activity that falls outside normal patterns.

These questions also help distinguish ordinary maintenance from misuse. A new remote-access process on a banking workstation during an unsolicited support call deserves different scrutiny from a scheduled session by an approved technician. Neither the product name nor its legitimate business purpose supplies that context by itself.

If someone has already granted suspicious access, AnyDesk advises contacting affected account providers, changing potentially compromised passwords, having the device checked by an IT specialist, and reporting the scam. In an enterprise, prompt escalation to the security team is essential so the response can consider both device access and account exposure.

A warning about borrowed legitimacy

Fortra’s report is a reminder that phishing is not limited to stolen passwords. It can be a route to convincing a person to delegate control of a trusted device.

The central defensive challenge is authorization: legitimate software, an encrypted connection, and an apparently helpful conversation can coexist with a fraudulent operator. Organizations that verify support requests and govern individual remote sessions will be better positioned to address that gap than those that equate a familiar application with a safe interaction.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Anthropic Updates Usage Policy, Adding Model Abuse and Deception Rules – Unite.AI
AI & Technology

Anthropic Updates Usage Policy, Adding Model Abuse and Deception Rules – Unite.AI

October 8, 2026
Apple Is Set To Show Off New Smart Home Devices At An October 13 Event
AI & Technology

Apple Is Set To Show Off New Smart Home Devices At An October 13 Event

October 8, 2026
Stord Secures 0M Credit Facility to Expand Fulfillment Network and AI – Unite.AI
AI & Technology

Stord Secures $400M Credit Facility to Expand Fulfillment Network and AI – Unite.AI

October 8, 2026
The New Stylophone Mini Packs In Iconic Sounds And Comes In Three Nifty Colors
AI & Technology

The New Stylophone Mini Packs In Iconic Sounds And Comes In Three Nifty Colors

October 8, 2026
Next Post
Joe Rogan renews nine-figure Spotify deal: report

Joe Rogan renews nine-figure Spotify deal: report

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Jane Doe’s text messages after alleged assault obtained

Jane Doe’s text messages after alleged assault obtained

October 2, 2026
Suspect and two victims dead in Virginia workplace shooting

Suspect and two victims dead in Virginia workplace shooting

October 3, 2026
Cat rescued after days trapped upside down in wall

Cat rescued after days trapped upside down in wall

October 7, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!