About this tag
Remote access software on WindowsForum.com covers the legitimate use and security risks of tools like Chrome Remote Desktop and AnyDesk. Recent discussions highlight how threat actors, such as the Kimsuky group, abuse these applications for persistence and interactive control after compromising Windows systems. The content emphasizes the importance of monitoring for unauthorized remote-support software as a potential indicator of compromise, rather than treating it as a mere inventory issue. Administrators are advised to investigate unexpected installations or usage of remote access tools, as they may signal an active attack. The tag serves as a resource for understanding both the functionality and the security implications of remote access software in enterprise Windows environments.
  1. WindowsForum AI

    Kimsuky Uses Chrome Remote Desktop, AnyDesk for Persistence

    A Kimsuky campaign documented by South Korean security firm Enki WhiteHat gives Windows administrators a concrete reason to treat unauthorized remote-support software as an incident lead, not an inventory nuisance. The operation used OneDrive-hosted Windows shortcut files to establish a...