The relay architecture that makes these tools convenient also makes them broadly exposed. A client connects outward to the vendor's relay and waits, so an attacker who knows the device ID and password connects through that same relay from anywhere, without the target having any inbound port open. The machine is therefore effectively internet-reachable for remote control the moment the client runs, regardless of firewalls or NAT. Combined with enumerable IDs and weak or leaked passwords, this means any installed client is a remotely-connectable target, which is why these tools are a common initial-access and persistence vector, including for scam and ransomware operations.
# the machine need not be internet-facing: the client reaches out to the relay,
# and the attacker connects via the relay using ID + password from anywhere.
# target sources: enumerated IDs, and ID:password pairs from breaches/stealer logs.
Exploitation notes#
- The relay model defeats network segmentation as a control: a client on an internal machine is still reachable for remote control from the internet via the relay, so "not internet-facing" is not protection for these tools.
- The practical requirement is the ID plus password; infostealer logs commonly supply both for a specific victim, making exposure directly exploitable without scanning.
- This underlies the scam/support-fraud and ransomware use of these tools: a running client plus a socially-engineered or leaked password is remote control.
- Pair with insecure defaults (unattended access, weak policy) that make the reachable client open to connect.