Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

PDQ Connect

PDQ Connect is a legitimate cloud-based remote monitoring and management (RMM) tool that has been repeatedly abused by threat actors as a remote-access capability rather than a traditional malware family. Reported abuse includes use by the Iranian APT group MuddyWater/TA450 and by cybercriminal activity tracked by Proofpoint, including TA558 and clusters targeting trucking and logistics firms for cargo theft. It has also appeared in generalized crimeware activity. Observed malicious use includes social-engineering victims into installing signed PDQ Connect MSI packages, including lures themed as Social Security statements such as ssa.msi, phishing and fake software-download pages impersonating products such as Notepad++, 7-Zip, Telegram, ChatGPT, and OpenAI, and delivery via malicious .exe or .msi files in logistics-focused campaigns. Once installed, attackers have used PDQ Connect for remote control and follow-on payload delivery, including installation of PatoRAT, and it has been observed downloading or deploying additional RMM tools such as ScreenConnect and SimpleHelp in tandem to preserve access. The tool provides software/package distribution, patch management, inventory, and remote-control functionality, which makes abuse blend with legitimate IT activity and evade some conventional detections because the binaries are signed and the infrastructure is legitimate. High-confidence artifacts mentioned in the content include storage of the API key at C:\ProgramData\PDQ\PDQConnectAgent\token and AhnLab EDR detection name Execution/EDR.PDQConnect.M12920. Red Canary reported that abuse of PDQ Connect largely diminished after PDQ rolled out new signed builds and updates in October 2025.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

PDQ Connect is a newer, cloud-based RMM that has seen abuse from APT groups like MuddyWater. While it has previously appeared in generalized crimeware, PDQ Connect abuse has largely diminished following the company’s rollout of new signed builds and updates in October 2025.

via red canary blogredcanary.com
TA558

While the actor favors VenomRAT, TA558 also distributes other commodity malware including njRAT, Remcos RAT, and recently XWorm and PDQ Connect.

via proofpointproofpoint.com
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1133External Remote ServicesEvidence1

"AnyDesk deployed for persistent remote access without IT authorisation"; "Abuse of legitimate RMM tools (Syncro, PDQ Connect) installed by third-party IT integrators on OT networks"

T1566PhishingEvidence2

SimpleHelp ... is often used in phishing campaigns involving “invitation” lures in which the victim is encouraged to download and execute an invite to a party (e.g. Ecard9140.exe ).

T1566.001Spearphishing AttachmentEvidence1

A common lure is themed as a Social Security statement ( ssa.msi ) in an attempt to convince the victim they need to run the file to retrieve their statement.

T1566.002Spearphishing LinkEvidence1

The initial infection occurs via specially crafted spam messages purporting to be from financial institutions or cell phone carriers with an overdue bill or electronic receipt of payment issued as an NF-e... Both messages link to a Dropbox file, which contains the malicious binary installer for the RMM tool.

Execution

2 techniques
T1204.001Malicious LinkEvidence1

"...emails have been found to contain malicious URLs to trick victims into downloading an MSI installer that, while masquerading as Microsoft Teams, ultimately deploys legitimate Remote Monitoring and Management (RMM) software like PDQ Connect..."

T1204.002Malicious FileEvidence1

Both messages link to a Dropbox file, which contains the malicious binary installer for the RMM tool.

Persistence

1 technique
T1133External Remote ServicesEvidence1

"AnyDesk deployed for persistent remote access without IT authorisation"; "Abuse of legitimate RMM tools (Syncro, PDQ Connect) installed by third-party IT integrators on OT networks"

Stealth

3 techniques
T1036MasqueradingEvidence1

Even when the file is renamed to something like party_invite.exe , or Voicemailaudioext.exe ... A common lure is themed as a Social Security statement ( ssa.msi ) ... using lures such as a document ( docmentfilecsm_jw98evavuqm5gb3.exe ) or an IRS tax-related file ( IRS-Statement_Pr2ui4J9cfA6YEu.exe ).

T1070.004File DeletionEvidence1

However, in some cases, we observed the threat actor installing an additional RMM tool and removing all security tools from the machine a few days after the initial compromise.

T1218System Binary Proxy ExecutionEvidence3

Because the installer is signed and generated by PDQ, it bypasses many basic reputation checks.

Lateral Movement

1 technique
T1021Remote ServicesEvidence2

Over the last few years, threat actors have flocked to exploit legitimate remote monitoring and management (RMM) tools—blue-chip IT software like ScreenConnect, LogMeIn Resolve, and PDQ Connect—blurring the line between legitimate IT administration and malicious intrusion.

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence1

Instead of leveraging them for initial access points to simply drop malware, attackers now use RMMs as 'a unified control hub' for command-and-control (C2) purposes as well as attack path redundancy.

T1071.001Web ProtocolsEvidence1

The network traffic these tools create is also disguised as regular traffic, with many tools using communication over HTTPS and connecting to resources which are part of the infrastructure provided by the application provider.

T1105Ingress Tool TransferEvidence3

They then use the remote capabilities of these agents to download and install Screen Connect after the initial compromise.

T1219Remote Access ToolsEvidence2

Talos observed the use of PDQ Connect and N-able remote access tools in this campaign... This campaign's objective is to lure the victims into installing an RMM tool, which allows the threat actor to take complete control of the target machine.

INDICATORS OF COMPROMISE

IOCs tracked for this family

27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
25 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 days ago
uri●●●●●●●●●●●●View more in app3 days ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching27

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.