Skip to content

RMS

Also known as: Gussdoor, Remote Manipulator System, RuRAT

CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices.

Linked Threat Actors

TA505

C2 Infrastructure

Hosting/VPS 100%

Last 7 days

Jul 2, 2026
C2 Hosts: 1

Further Reading