The Fake IT Guy: When Remote Access Software Is the Scam
Most scams are after your password. This one skips that step completely. It asks your employee to install a program — and then the attacker simply sits down at the keyboard.
Researchers at ANY.RUN have been tracking a phishing campaign that now spans 46 countries, and the United States is the top target at roughly 45% of the activity they observed. The emails are unremarkable on purpose: a tax notice, a past-due invoice, a shipping update, a shared PDF. Click through, and what lands on the machine is not a virus. It is a real, commercially licensed remote support tool — ScreenConnect, ConnectWise, LogMeIn Rescue. The same category of software my team uses to fix your laptop without driving across Tucson.
That is exactly why it works.
Why your antivirus sits this one out
The software is genuinely legitimate
These are signed, paid, above-board products used by IT departments everywhere. Your antivirus has no signature to match and no reason to raise its hand. Blocking the whole category outright would break the legitimate support your business depends on. This is why endpoint protection that only asks “is this file known to be bad?” will wave this straight through. What matters is what a program does after it is installed, not what it is called.
Once it is running, it looks like a normal workday
A remote session in the middle of the afternoon is not suspicious. It is Tuesday. Somebody is always fixing something. The attacker is not smashing through your firewall; they are walking through a door your business deliberately left unlocked for IT. And they do not stay put — researchers found 94% of the campaign’s hosting infrastructure was live for a single day and then vanished, which makes blocking it by address close to useless.

What this looks like in a small business
Here is the version I worry about. Your bookkeeper gets an email about an invoice that is supposedly past due. She opens it, gets a prompt to install a viewer so she can read the document, and clicks yes — because she has clicked yes to a hundred harmless prompts before. Ten minutes later, someone she has never met is watching her screen.
They do not need to steal a password at that point. She is already signed into the bank portal, the accounting system, and email. They are inside a session that everything already trusts. From there it is changing wire instructions, reading the email history to learn how your company talks about money, or quietly preparing a ransomware deployment for the following week — which is the moment your secure backups stop being a line item on an invoice and start being the entire business.
The one rule that stops almost all of it
Nobody legitimate will ever contact you out of the blue and ask you to install remote access software.
Not us. Not Microsoft. Not your bank, your printer vendor, or the IRS. Real IT support is something you asked for, from a company you already work with, at a number you already had. If a request for remote access shows up unsolicited — email, popup, phone call, or text — the answer is no, every single time. Then you verify by calling the company back on a number you look up yourself, not one from the message.
It is the same instinct behind the login request you should never approve: if you did not start it, do not approve it.
What you can do this week
- Say the rule out loud at your next staff meeting. “We will never email you and ask you to install remote software. If anyone does, it is fake, and you come tell me.” Two sentences. That is the whole training.
- Write down which remote tools you actually use. If your IT support uses one specific tool, everyone should know its name. Anything else appearing on a screen is a red flag, not a mystery to be solved quietly.
- Take local admin rights away from day-to-day accounts. If your bookkeeper cannot install software without you, this attack dies at the prompt. This is the single highest-value change on the list, and it costs nothing.
- Tighten the front end. Good spam and virus filtering strips out most of these lures before anyone has a decision to make. You cannot click what never arrives.
- Agree on how you verify money. Any change to wire details, bank accounts, or payment instructions gets confirmed by a phone call to a known number. No exceptions, no matter who appears to be asking.
- Give people permission to be wrong. The employee who says “I think I clicked something” in the first ten minutes saves you a very expensive week. Ongoing security awareness training works because it makes speaking up normal.
The bottom line
This attack does not beat your technology. It beats a habit — the habit of saying yes to a prompt because saying yes is how the day usually goes. The fix is not a bigger firewall. It is one clear rule that everyone in your building knows, plus the boring groundwork of limiting who can install what.
If you are not sure who can install software on your machines right now, that is worth finding out this week rather than after somebody clicks. More plain-English breakdowns like this one are on our blog.
Not sure who can install software on your computers?
We handle this for small businesses all over Southern Arizona — locking down admin rights, filtering the bad email out, and answering the phone at 2 a.m. when something goes wrong. See our small business cyber security solutions.
Send us a message
Have a question about something in this article, or want a second opinion on how your systems are set up? Send it over and I will get back to you personally.
— Nemuel Cruz, Incognito Cyber Security


