Cybersecurity 3 min read September 8, 2026

Should we worry about fake remote-access requests?

A client forwarded us a document-sharing email that ended with a prompt to install a remote-access tool. The uncomfortable part: the tool itself was completely real.

The question

"One of our execs got an email that looked like a normal document-share request — nothing weird about it. But after 'verifying' through a couple of screens, it wanted them to install a remote-support app to view the file properly. They didn't do it, but now everyone's asking: how would we even tell that apart from a legitimate IT request?"

Good instinct to stop and ask, because this exact pattern is now being sold as a subscription service to attackers.

What we told them

A phishing-as-a-service kit called BlueKit is behind a wave of these attacks. It's aimed specifically at executives, and it's built around a technique called browser-in-the-middle: the victim is shown a real, working version of a login page — Microsoft 365, Google, whatever fits the lure — streamed through the attacker's server, so it passes the "does this look right" test almost every user runs instinctively.

The document-share email is just the entry point. Once someone clicks through, they're routed into what looks like a document viewer that "requires" a plugin or support tool to display properly. That tool is a legitimate remote-access client, configured ahead of time to connect back to an account the attacker controls. There's no malware to catch — security software sees a normal, signed application doing exactly what it's designed to do. The only difference is who's on the other end of the connection.

Here's the actual test: a legitimate IT request for remote access never arrives by surprise from a document link. If you or your provider needs to remote into a machine, it's because someone opened a ticket, made a call, or otherwise initiated contact first. An unsolicited prompt to install a remote-access tool — especially one wrapped inside a "verify to view this file" flow — is the pattern to distrust, regardless of how convincing the surrounding pages look.

  • Treat any install prompt that follows a document link as suspicious by default, even if the login screen looked correct.
  • Confirm remote-access requests through a channel you started yourself — call your provider back on a known number, don't reply to the email or click through it.
  • Executives are the deliberate target here. If your leadership team hasn't heard about this pattern specifically, that's worth a two-minute heads-up today.
The takeaway

The tool being installed is real, so your antivirus won't save you here — the giveaway is the sequence of events, not the software. Remote access should always be something you asked for, never something a document link talks you into.

Got a question like this one?

Send it over — 20 minutes, no pitch, a straight answer either way.