The Fake IT Guy: When Remote Access Software Is the Scam

Sep 9, 2026Incognito CyberSecurity

The Fake IT Guy: When Remote Access Software Is the Scam

🇲🇽 Leer en Español →

Most scams are after your password. This one skips that step completely. It asks your employee to install a program — and then the attacker simply sits down at the keyboard.

Researchers at ANY.RUN have been tracking a phishing campaign that now spans 46 countries, and the United States is the top target at roughly 45% of the activity they observed. The emails are unremarkable on purpose: a tax notice, a past-due invoice, a shipping update, a shared PDF. Click through, and what lands on the machine is not a virus. It is a real, commercially licensed remote support tool — ScreenConnect, ConnectWise, LogMeIn Rescue. The same category of software my team uses to fix your laptop without driving across Tucson.

That is exactly why it works.

Why your antivirus sits this one out

The software is genuinely legitimate

These are signed, paid, above-board products used by IT departments everywhere. Your antivirus has no signature to match and no reason to raise its hand. Blocking the whole category outright would break the legitimate support your business depends on. This is why endpoint protection that only asks “is this file known to be bad?” will wave this straight through. What matters is what a program does after it is installed, not what it is called.

Once it is running, it looks like a normal workday

A remote session in the middle of the afternoon is not suspicious. It is Tuesday. Somebody is always fixing something. The attacker is not smashing through your firewall; they are walking through a door your business deliberately left unlocked for IT. And they do not stay put — researchers found 94% of the campaign’s hosting infrastructure was live for a single day and then vanished, which makes blocking it by address close to useless.

Infographic with three cards: it looks legitimate, the bait is boring, and one click gives full control of your screen.

What this looks like in a small business

Here is the version I worry about. Your bookkeeper gets an email about an invoice that is supposedly past due. She opens it, gets a prompt to install a viewer so she can read the document, and clicks yes — because she has clicked yes to a hundred harmless prompts before. Ten minutes later, someone she has never met is watching her screen.

They do not need to steal a password at that point. She is already signed into the bank portal, the accounting system, and email. They are inside a session that everything already trusts. From there it is changing wire instructions, reading the email history to learn how your company talks about money, or quietly preparing a ransomware deployment for the following week — which is the moment your secure backups stop being a line item on an invoice and start being the entire business.

The one rule that stops almost all of it

Nobody legitimate will ever contact you out of the blue and ask you to install remote access software.

Not us. Not Microsoft. Not your bank, your printer vendor, or the IRS. Real IT support is something you asked for, from a company you already work with, at a number you already had. If a request for remote access shows up unsolicited — email, popup, phone call, or text — the answer is no, every single time. Then you verify by calling the company back on a number you look up yourself, not one from the message.

It is the same instinct behind the login request you should never approve: if you did not start it, do not approve it.

What you can do this week

  1. Say the rule out loud at your next staff meeting. “We will never email you and ask you to install remote software. If anyone does, it is fake, and you come tell me.” Two sentences. That is the whole training.
  2. Write down which remote tools you actually use. If your IT support uses one specific tool, everyone should know its name. Anything else appearing on a screen is a red flag, not a mystery to be solved quietly.
  3. Take local admin rights away from day-to-day accounts. If your bookkeeper cannot install software without you, this attack dies at the prompt. This is the single highest-value change on the list, and it costs nothing.
  4. Tighten the front end. Good spam and virus filtering strips out most of these lures before anyone has a decision to make. You cannot click what never arrives.
  5. Agree on how you verify money. Any change to wire details, bank accounts, or payment instructions gets confirmed by a phone call to a known number. No exceptions, no matter who appears to be asking.
  6. Give people permission to be wrong. The employee who says “I think I clicked something” in the first ten minutes saves you a very expensive week. Ongoing security awareness training works because it makes speaking up normal.

The bottom line

This attack does not beat your technology. It beats a habit — the habit of saying yes to a prompt because saying yes is how the day usually goes. The fix is not a bigger firewall. It is one clear rule that everyone in your building knows, plus the boring groundwork of limiting who can install what.

If you are not sure who can install software on your machines right now, that is worth finding out this week rather than after somebody clicks. More plain-English breakdowns like this one are on our blog.

Not sure who can install software on your computers?

We handle this for small businesses all over Southern Arizona — locking down admin rights, filtering the bad email out, and answering the phone at 2 a.m. when something goes wrong. See our small business cyber security solutions.

Book a complimentary visit →

Send us a message

Have a question about something in this article, or want a second opinion on how your systems are set up? Send it over and I will get back to you personally.

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

— Nemuel Cruz, Incognito Cyber Security

About the author

Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News