Blog
/
/
August 3, 2022

The Risks of Remote Access Tools

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
03
Aug 2022
Discover how remote access tools in exploitations across OT/ICS and corporate environments benefit from Darktrace's product suite.

Understanding remote access tools

In 2022, remote access tools continue to provide versatile support to organizations. By controlling devices remotely from across the globe, IT teams save on response costs, travel times, and can receive remote support from external parties like contractors [1 & 2]. This is particularly relevant in cases involving specialty machines such as OT/ICS systems where physical access is sometimes limited. These tools, however, come with their own risks. The following blog will discuss these risks and how they can be addressed (particularly in OT environments) by looking at two exploit examples from the popular sphere and within the Darktrace customer base. 

What are remote access tools?

One of the most popular remote tools is TeamViewer, a comprehensive videoconferencing and remote management tool which can be used on both desktop and handheld devices[3]. Like other sophisticated tools, when it works as intended, it can seem like magic. However, remote access tools can be exploited and may grant privileged network access to potential threat actors. Although TeamViewer needs to be installed on both perpetrator and victim devices, if an attacker has access to a misconfigured TeamViewer device, it becomes trivial to establish a foothold and deploy malware. 

How secure is remote access?

Security vulnerabilities in remote access tools

In early 2021, remote access tooling was seen on a new scale against the City of Oldsmar’s water treatment plant [4] (Figure 1). Oldsmar manages chemical concentration levels in the water for a 15,000-person city. The water treatment plant had been using TeamViewer to allow employees to share screens and work through IT issues. However, in February an employee noticed he had lost control of his mouse cursor. Initially he was unconcerned; the employee assumed that the cursor was being controlled by his boss, who regularly connected to the computer to monitor the facility’s systems. A few hours later though, the employee again saw his cursor moving out of his control and this time noticed that it was attempting to change levels of sodium hydroxide in the water supply (which is extremely dangerous for human consumption). Thankfully, the employee was able to quickly spot the changes and return them to their normal level. When looking back at the event, the key question posed by officials was where exactly the vulnerability was located in their security stack. [5]. The answer was unclear.

Photograph of compromised water plant in Florida 
Figure 1: Photograph of compromised water plant in Florida 

Tactics and strategies

When attackers get initial network access, the primary challenge for any enterprise is identifying a) that a device compromise has happened and b) how it happened. These were the same challenges seen in the Oldsmar attack. When the first physical signs of compromise occurred (cursor movement), the impacted user was still unsure whether the activity was malicious. A detailed investigation from Dragos revealed the how: evidence of a watering hole, reconnaissance activity a month prior, a targeted variant of the Tofsee botnet, and the potential presence of two separate threat actors [6 & 7]. The answer to both questions pointed to a complex attack. However, with Darktrace these questions become less important. 

How Darktrace stops compromised remote access

Darktrace does not rely on signatures but instead has AI-based models for live detection of these tools and anomalies within the wider network. Regardless of the security ‘hole’, live detection gives security teams the potential to respond in near-live time.

According to Darktrace’s Chief Product Officer, Max Heinemeyer, the Oldsmar attack was possible because it “Abused off-the-shelf tools that were already used by the client, specifically TeamViewer. This tactic, which targeted the domain controller as the initial vector, made the malware deployment easy and effective.” [8]. 

Darktrace has multiple DETECT models to provide visibility over anomalous TeamViewer or remote access tool usage:

·      Compliance / Incoming Remote Access Tool

·      Compliance / Remote Management Tool On Client

·      Compliance / Remote Management Tool On Server

·      Device / Activity Identifier / Teamviewer 

General incoming privileged connections:

·      Compliance / Incoming Remote Desktop

·      Compliance / Incoming SSH

Industrial DETECT can also highlight any new or unusual changes in ICS/OT systems:

·      ICS / Incoming ICS Command

·      ICS / Incoming RDP And ICS Commands

·      ICS / Uncommon ICS Error

Darktrace gives security teams the opportunity for a proactive response, and it is up to those teams to utilize that opportunity. In recent months our SOC Team have also seen remote access controls being abused for high-profile threats. In one example, Darktrace detected a ransomware attack supported by the installation of AnyDesk. 

Initial detection of compromise

In May a company’s mail server was detected making multiple external requests for an unusual file ‘106.exe’ using a PowerShell agent (6b79549200af33bf0322164f8a4d56a0fa08a5a62ab6a5c93a6eeef2065430ce). Although some requests were directed to sinkholes, many were otherwise successful. Subsequently a DDL file with hash f126ce9014ee87de92e734c509e1b5ab71ffb2d5a8b27171da111f96f3ba0e75 (marked by VirusTotal as malicious) was downloaded. This was followed by the installation of AnyDesk: a remote access tool likely deployed for backdoor purposes during further compromises. It is clear the threat actor then moved on to reconnaissance, with new Mimikatz use and a large volume of ICMP and SMBv.1 scanning sessions using a default credential. DCE-RPC calls were also made to the Netlogon service, suggesting a possible attempt to exploit 2020’s Zerologon vulnerability (CVE-2020-1472) [9]. When the customer then discovered a ransom note pertaining to LV (repurposed REvil), Darktrace analysts helped them to re-configure Darktrace RESPOND and turn it to active rather than human confirmation mode (Figure 2). 

Figure 2: Capture of LV ransom note provided by customer

Whilst in this instance the tool was not used for initial access, it was still an important contingency tool to ensure the threat actor’s persistency as the customer tried to respond to the ongoing breach. Yet it was the visibility provided by Darktrace model detection and changes to RESPOND configuration which ensured the customer kept up with this actor and reduced the impact of the attack. 

Looking back at Oldsmar, it is clear that being aware of remote access tools is only half the battle. More importantly, most organizations are asking if their use in attacks can be prevented in the first place. As an off-the-shelf tool, restricting TeamViewer use seems like an easy solution but such tools are often essential for maintenance and support operations. Even if limited to privileged users, these accounts are also subject to potential compromise. Instead, companies can take a large-scale view and consider the environment in which the Oldsmar attack occurred. 

How IT & OT convergence complicated this attack

In this context, the separation of OT and IT systems is a potential solution - if attackers cannot access at-risk systems, then they also cannot attack those systems. However, with recent discourse around the IT-OT convergence and increased use of IoT devices, this separation is increasingly challenging to implement [10]. Complex networking designs, stringent patching requirements and ever-changing business/operational needs are all big considerations when establishing industrial security. In fact, Tenable’s CEO Amit Yoran encouraged less separation following Oldsmar: “There’s business reasons and efficiency reasons that you might want to connect those to be able to predict when parts are going to fail or when outages are going to occur [sic].” [11]. 

When neither addressing remote access use or industrial set-up provides a quick solution, then security teams need to look to third-party support to stop similar attacks. In addition to Darktrace DETECT, our Darktrace PREVENT range with PREVENT/Attack Surface Management (ASM) can also alert security teams to internet-facing devices at risk of remote access exploitation. ASM actively queries the Shodan API for open ports on company websites and exposed servers. This highlights those assets which might be vulnerable to this type of remote access.   

Conclusion

In conclusion, TeamViewer and other remote access tools offer a lot of convenience for security teams but also for attackers. Attackers can remotely access important systems including those in the industrial network and install malware using remote access tools as leverage. Security teams need to know both their normal authorized activities and how to enforce them. With Darktrace DETECT, the tools are given transparency, with Darktrace RESPOND they can be blocked, and now Darktrace PREVENT/ASM helps to mitigate the risk of attack before it happens. As the professional world continues to embrace hybrid working, it becomes increasingly crucial to embrace these types of products and ensure protection against the dangers of unwanted remote access. 

Thanks to Connor Mooney for his contributions to this blog.

Appendices

References 

[1] https://goabacus.com/advantages-and-disadvantages-of-remote-access-service/ 

[2] https://blog.ericom.com/advantages-of-remote-access/ 

[3] https://www.teamviewer.com/en/documents/ 

[4] https://www.wired.com/story/oldsmar-florida-water-utility-hack/ 

[5 & 11] https://www.bankinfosecurity.com/ot-it-integration-raises-risk-for-water-providers-experts-say-a-18841 

[6] https://www.dragos.com/blog/industry-news/a-new-water-watering-hole/ 

[7] https://www.dragos.com/blog/industry-news/recommendations-following-the-oldsmar-water-treatment-facility-cyber-attack/

[8] https://customerportal.darktrace.com/darktrace-blogs/get-blog/53  

[9] https://www.crowdstrike.com/blog/cve-2020-1472-zerologon-security-advisory/

[10] https://www.mckinsey.com/business-functions/operations/our-insights/converge-it-and-ot-to-turbocharge-business-operations-scaling-power

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
Dylan Hinz
Cyber Analyst
Gabriel Few-Wiegratz
Product Marketing Manager, Exposure Management and Incident Readiness
Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

Network

/

February 19, 2025

Darktrace Releases Annual 2024 Threat Insights

Default blog imageDefault blog image

Introduction: Darktrace’s threat research

Defenders must understand the threat landscape in order to protect against it. They can do that with threat intelligence.

Darktrace approaches threat intelligence with a unique perspective. Unlike traditional security vendors that rely on established patterns from past incidents, it uses a strategy that is rooted in the belief that identifying behavioral anomalies is crucial for identifying both known and novel threats.

For Darktrace analysts and researchers, the incidents detected by the AI solution mark the beginning of a deeper investigation, aiming to connect mitigated threats to wider trends from across the threat landscape. Through hindsight analysis, the Darktrace Threat Research team has highlighted numerous threats, including zero-day, n-day, and other novel attacks, showcasing their evolving nature and Darktrace’s ability to identify them.

In 2024, the Threat Research team observed major trends around vulnerabilities in internet-facing systems, new and re-emerging ransomware strains, and sophisticated email attacks. Read on to discover some of our key insights into the current cybersecurity threat landscape.

Multiple campaigns target vulnerabilities in internet-facing systems

It is increasingly common for threat actors to identify and exploit newly discovered vulnerabilities in widely used services and applications, and in some cases, these vulnerability exploitations occur within hours of disclosure.

In 2024, the most significant campaigns observed involved the ongoing exploitation of zero-day and n-day vulnerabilities in edge and perimeter network technologies. In fact, in the first half of the year, 40% of all identified campaign activity came from the exploitation of internet-facing devices. Some of the most common exploitations involved Ivanti Connect Secure (CS) and Ivanti Policy Secure (PS) appliances, Palo Alto Network (PAN-OS) firewall devices, and Fortinet appliances.

Darktrace helps security teams identify suspicious behavior quickly, as demonstrated with the critical vulnerability in PAN-OS firewall devices. The vulnerability was publicly disclosed on April 11, 2024, yet with anomaly-based detection, Darktrace’s Threat Research team was able to identify a range of suspicious behavior related to exploitation of this vulnerability, including command-and-control (C2) connectivity, data exfiltration, and brute-forcing activity, as early as March 26.

That means that Darktrace and our Threat Research team detected this Common Vulnerabilities and Exposure (CVE) exploitation 16 days before the vulnerability was disclosed. Addressing critical vulnerabilities quickly massively benefits security, as teams can reduce their effectiveness by slowing malicious operations and forcing attackers to pursue more costly and time-consuming methods.

Persistent ransomware threats continue to evolve

The continued adoption of the Ransomware-as-a-Service (RaaS) model provides even less experienced threat actors with the tools needed to carry out disruptive attacks, significantly lowering the barrier to entry.

The Threat Research team tracked both novel and re-emerging strains of ransomware across the customer fleet, including Akira, LockBit, and Lynx. Within these ransomware attempts and incidents, there were notable trends in attackers’ techniques: using phishing emails as an attack vector, exploiting legitimate tools to mask C2 communication, and exfiltrating data to cloud storage services.

Read the Annual 2024 Threat Report for the complete list of prominent ransomware actors and their commonly used techniques.

Onslaught of email threats continues

With a majority of attacks originating from email, it is crucial that organizations secure the inboxes and beyond.

Between December 21, 2023, and December 18, 2024, Darktrace / EMAIL detected over 30.4 million phishing emails across the fleet. Of these, 70% successfully bypassed Domain-based Message Authentication, Reporting, and Conformance (DMARC) verification checks and 55% passed through all other existing layers of customer email security.

The abuse of legitimate services and senders continued to be a significant method for threat actors throughout 2024. By leveraging trusted platforms and domains, malicious actors can bypass traditional security measures and increase the likelihood of their phishing attempts being successful.

This past year, there was a substantial use of legitimately authenticated senders and previously established domains, with 96% of phishing emails detected by Darktrace / EMAIL utilizing existing domains rather than registering new ones.

These are not the only types of email attacks we observed. Darktrace detected over 2.7 million emails with multistage payloads.

While most traditional cybersecurity solutions struggle to cover multiple vectors and recognize each stage of complex attacks as part of wider malicious activity, Darktrace can detect and respond across email, identities, network, and cloud.

Conclusion

The Darktrace Threat Research team continues to monitor the ever-evolving threat landscape. Major patterns over the last year have revealed the importance of fast-acting, anomaly-based detection like Darktrace provides.

For example, response speed is essential when campaigns target vulnerabilities in internet-facing systems, and these vulnerabilities can be exploited by attackers within hours of their disclosure if not even before that.

Similarly, anomaly-based detection can identify hard to find threats like ransomware attacks that increasingly use living-off-the-land techniques and legitimate tools to hide malicious activity. A similar pattern can be found in the realm of email security, where attacks are also getting harder to spot, especially as they frequently exploit trusted senders, use redirects via legitimate services, and craft attacks that bypass DMARC and other layers of email security.

As attacks appear with greater complexity, speed, and camouflage, defenders must have timely detection and containment capabilities to handle all emerging threats. These hard-to-spot attacks can be identified and stopped by Darktrace.

Download the full report

Discover the latest threat landscape trends and recommendations from the Darktrace Threat Research team.

Continue reading
About the author
The Darktrace Threat Research Team

Blog

/

OT

/

February 18, 2025

Unifying IT & OT With AI-Led Investigations for Industrial Security

Default blog imageDefault blog image

As industrial environments modernize, IT and OT networks are converging to improve efficiency, but this connectivity also creates new attack paths. Previously isolated OT systems are now linked to IT and cloud assets, making them more accessible to attackers.

While organizations have traditionally relied on air gaps, firewalls, data diodes, and access controls to separate IT and OT, these measures alone aren’t enough. Threat actors often infiltrate IT/Enterprise networks first then exploit segmentation, compromising credentials, or shared IT/OT systems to move laterally, escalate privileges, and ultimately enter the OT network.

To defend against these threats, organizations must first ensure they have complete visibility across IT and OT environments.

Visibility: The first piece of the puzzle

Visibility is the foundation of effective industrial cybersecurity, but it’s only the first step. Without visibility across both IT and OT, security teams risk missing key alerts that indicate a threat targeting OT at their earliest stages.

For Attacks targeting OT, early stage exploits often originate in IT environments, adversaries perform internal reconnaissance among other tactics and procedures but then laterally move into OT first affecting IT devices, servers and workstations within the OT network. If visibility is limited, these threats go undetected. To stay ahead of attackers, organizations need full-spectrum visibility that connects IT and OT security, ensuring no early warning signs are missed.

However, visibility alone isn’t enough. More visibility also means more alerts, this doesn’t just make it harder to separate real threats from routine activity, but bogs down analysts who have to investigate all these alerts to determine their criticality.

Investigations: The real bottleneck

While visibility is essential, it also introduces a new challenge: Alert fatigue. Without the right tools, analysts are often occupied investigating alerts with little to no context, forcing them to manually piece together information and determine if an attack is unfolding. This slows response times and increases the risk of missing critical threats.

Figure 1: Example ICS attack scenario

With siloed visibility across IT and OT each of these events shown above would be individually alerted by a detection engine with little to no context nor correlation. Thus, an analyst would have to try to piece together these events manually. Traditional security tools struggle to keep pace with the sophistication of these threats, resulting in an alarming statistic: less than 10% of alerts are thoroughly vetted, leaving organizations vulnerable to undetected breaches. As a result, incidents inevitably follow.

Darktrace’s Cyber AI Analyst uses AI-led investigations to improve workflows for analysts by automatically correlating alerts wherever they occur across both IT and OT. The multi-layered AI engine identifies high-priority incidents, and provides analysts with clear, actionable insights, reducing noise and highlighting meaningful threats. The AI significantly alleviates workloads, enabling teams to respond faster and more effectively before an attack escalates.

Overcoming organizational challenges across IT and OT

Beyond technical challenges like visibility and alert management, organizational dynamics further complicate IT-OT security efforts. Fundamental differences in priorities, workflows, and risk perspectives create challenges that can lead to misalignment between teams:

Non-transferable practices: IT professionals might assume that cybersecurity practices from IT environments can be directly applied to OT environments. This can lead to issues, as OT systems and workflows may not handle IT security processes as expected. It's crucial to recognize and respect the unique requirements and constraints of OT environments.

Segmented responsibilities: IT and OT teams often operate under separate organizational structures, each with distinct priorities, goals, and workflows. While IT focuses on data security, network integrity, and enterprise applications, OT prioritizes uptime, reliability, and physical processes.

Different risk perspectives: While IT teams focus on preventing cyber threats and regulatory violations, OT teams prioritize uptime and operational reliability making them drawn towards asset inventory tools that provide no threat detection capability.

Result: A combination of disparate and ineffective tools and misaligned teams can make any progress toward risk reduction at an organization seem impossible. The right tools should be able to both free up time for collaboration and prompt better communication between IT and OT teams where it is needed. However, different size operations structure their IT and OT teams differently which impacts the priorities for each team.

In real-world scenarios, small IT teams struggle to manage security across both IT and OT, while larger organizations with OT security teams face alert fatigue and numerous false positives slowing down investigations and hindering effective communication with the IT security teams.

By unifying visibility and investigations, Darktrace / OT helps organizations of all sizes detect threats earlier, streamline workflows, and enhance security across both IT and OT environments. The following examples illustrate how AI-driven investigations can transform security operations, improving detection, investigation, and response.

Before and after AI-led investigation

Before: Small manufacturing company

At a small manufacturing company, a 1-3 person IT team juggles everything from email security to network troubleshooting. An analyst might see unusual traffic through the firewall:

  • Unusual repeated outbound traffic from an IP within their OT network destined to an unidentifiable external IP.

With no dedicated OT security tools and limited visibility into the industrial network, they don’t know what the internal device in question is, if it is beaconing to a malicious external IP, and what it may be doing to other devices within the OT network. Without a centralized dashboard, they must manually check logs, ask operators about changes, and hunt for anomalies across different systems.

After a day of investigation, they concluded the traffic was not to be expected activity. They stop production within their smaller OT network, update their firewall rules and factory reset all OT devices and systems within the blast radius of the IP device in question.

After: Faster, automated response with Cyber AI Analyst

With Darktrace / OT and Cyber AI Analyst, the IT team moves from reactive, manual investigations to proactive, automated threat detection:

  • Cyber AI Analyst connects alerts across their IT and OT infrastructure temporally mapping them to attack frameworks and provides contextual analysis of how alerts are linked, revealing in real time attackers attempting lateral movement from IT to OT.
  • A human-readable incident report explains the full scope of the incident, eliminating hours of manual investigation.
  • The team is faster to triage as they are led directly to prioritized high criticality alerts, now capable of responding immediately instead of wasting valuable time hunting for answers.

By reducing noise, providing context, and automating investigations, Cyber AI Analyst transforms OT security, enabling small IT teams to detect, understand, and respond to threats—without deep OT cybersecurity expertise.

Before: Large critical infrastructure organization

In large critical infrastructure operations, OT and IT teams work in separate silos. The OT security team needs to quickly assess and prioritize alerts, but their system floods them with notifications:

  • Multiple new device connected to the ICS network alerts
  • Multiple failed logins to HMI detected
  • Multiple Unusual Modbus/TCP commands detected
  • Repeated outbound OT traffic to IT destinations

At first glance, these alerts seem important, but without context, it’s unclear whether they indicate a routine error, a misconfiguration, or an active cyber-attack. They might ask:

  • Are the failed logins just a mistake, or a brute-force attempt?
  • Is the outbound traffic part of a scheduled update, or data exfiltration?

Without correlation across events, the engineer must manually investigate each one—checking logs, cross-referencing network activity, and contacting operators—wasting valuable time. Meanwhile, if it’s a coordinated attack, the adversary may already be disrupting operations.

After: A new workflow with Cyber AI Analyst

With Cyber AI Analyst, the OT security team gets clear, automated correlation of security events, making investigations faster and more efficient:

  • Automated correlation of OT threats: Instead of isolated alerts, Cyber AI Analyst stitches together related events, providing a single, high-confidence incident report that highlights key details.
  • Faster time to meaning: The system connects anomalous behaviors (e.g., failed logins, unusual traffic from an HMI, and unauthorized PLC modifications) into a cohesive narrative, eliminating hours of manual log analysis.
  • Prioritized and actionable alerts: OT security receives clear, ranked incidents, immediately highlighting what matters most.
  • Rapid threat understanding: Security teams know within minutes whether an event is a misconfiguration or a cyber-attack, allowing for faster containment.

With Cyber AI Analyst, large organizations cut through alert noise, accelerate investigations, and detect threats faster—without disrupting OT operations.

An AI-led approach to industrial cybersecurity

Security vendors with a primary focus on IT may lack insight into OT threats. Even OT-focused vendors have limited visibility into IT device exploitation within OT networks, leading to failed ability to detect early indicators of compromise. A comprehensive solution must account for the unique characteristics of various OT environments.

In a world where industrial security is no longer just about protecting OT but securing the entire digital-physical ecosystem as it interacts with the OT network, Darktrace / OT is an AI-driven solution that unifies visibility across IT, IoT and OT, Cloud into one cohesive defense strategy.

Whether an attack originates from an external breach, an insider threat, a supply chain compromise, in the Cloud, OT, or IT domains Cyber AI Analyst ensures that security teams see the full picture - before disruption occurs.

Learn more about Darktrace / OT 

  • Unify IT and OT security under a single platform, ensuring seamless communication and protection for all interconnected devices.
  • Maintain uptime with AI-driven threat containment, stopping attacks without disrupting production.
  • Mitigate risks with or without patches, leveraging MITRE mitigations to reduce attack opportunities.

Download the solution brief to see how Darktrace secures critical infrastructure.

Continue reading
About the author
Daniel Simonds
Director of Operational Technology
Your data. Our AI.
Elevate your network security with Darktrace AI