The question
Good instinct to stop and ask, because this exact pattern is now being sold as a subscription service to attackers.
What we told them
A phishing-as-a-service kit called BlueKit is behind a wave of these attacks. It's aimed specifically at executives, and it's built around a technique called browser-in-the-middle: the victim is shown a real, working version of a login page — Microsoft 365, Google, whatever fits the lure — streamed through the attacker's server, so it passes the "does this look right" test almost every user runs instinctively.
The document-share email is just the entry point. Once someone clicks through, they're routed into what looks like a document viewer that "requires" a plugin or support tool to display properly. That tool is a legitimate remote-access client, configured ahead of time to connect back to an account the attacker controls. There's no malware to catch — security software sees a normal, signed application doing exactly what it's designed to do. The only difference is who's on the other end of the connection.
Here's the actual test: a legitimate IT request for remote access never arrives by surprise from a document link. If you or your provider needs to remote into a machine, it's because someone opened a ticket, made a call, or otherwise initiated contact first. An unsolicited prompt to install a remote-access tool — especially one wrapped inside a "verify to view this file" flow — is the pattern to distrust, regardless of how convincing the surrounding pages look.
- Treat any install prompt that follows a document link as suspicious by default, even if the login screen looked correct.
- Confirm remote-access requests through a channel you started yourself — call your provider back on a known number, don't reply to the email or click through it.
- Executives are the deliberate target here. If your leadership team hasn't heard about this pattern specifically, that's worth a two-minute heads-up today.
The tool being installed is real, so your antivirus won't save you here — the giveaway is the sequence of events, not the software. Remote access should always be something you asked for, never something a document link talks you into.