The Threats Your Antivirus Can’t See

Threats that Antivirus dont see

Over the past couple of weeks we’ve seen a lot more of a kind of attack that doesn’t look like a virus and isn’t really a trojan. There’s no malware for your antivirus to catch — because the attacker never uses malware. They trick a staff member into installing legitimate remote-access software, then quietly walk in through the front door.

This is a genuine shift in how attackers are operating, and it’s catching well-protected businesses out. Your antivirus is working perfectly — it simply has nothing to flag. Below is exactly what we’re seeing, why it slips past your defences (and ours), and a practical plan to shut it down.

The short version
  • Attackers are skipping malware and instead tricking staff into installing legitimate remote-access tools (like TeamViewer or AnyDesk).
  • Because that software is genuine and signed, antivirus never flags it — and neither our monitoring nor yours gets an alert.
  • Two delivery methods dominate: fake “your reports are ready, click to download” portal emails, and lure PDFs that carry a download link past every filter.
  • The single most effective fixes: ban file-download portals, send documents as real attachments, and teach staff to hover and read the real destination URL.
  • If you suspect it’s happened — disconnect the machine and ring PIP straight away.
0antivirus alerts raised
1 clickis all it takes to let them in
24/7remote access once installed
Legitsigned software, abused
Why it’s invisible

How they outsmart your antivirus

Antivirus, anti-malware and endpoint monitoring — including the monitoring PIP runs — are all built to answer one question: is this software malicious? They look for known-bad code, suspicious behaviour and malware signatures. It’s a model that has protected businesses for decades, and against actual malware it works.

These attacks defeat that model by never using malware at all. TeamViewer, AnyDesk and similar remote-access tools are genuine, digitally signed, widely trusted programs used by millions of legitimate businesses — including IT providers. When one installs, your antivirus sees a known-good application and correctly does nothing. The malice isn’t in the code; it’s in who is holding the other end and how they got there. That’s why no alert reaches you, and none reaches us.

01 LureFake “reports ready” email or PDF link
02 ClickStaff download the “document”
03 InstallA real remote-access tool installs
04 SilentAntivirus sees trusted software — no alert
05 AccessAttacker has 24/7 remote control
No malware is ever used — so antivirus, anti-trojan and monitoring stay completely silent.

The whole chain runs through legitimate software and a single human decision.

The skill that stops it

Learn to hover before you click

Nearly every one of these attacks depends on a person clicking a link that isn’t what it claims to be. The good news: the real destination is almost always visible before you click. On a computer, hover your mouse over any link (don’t click) and the true address appears — usually in the bottom-left corner of your browser or email program. On a phone, press and hold the link to preview it.

From: Secure Document Delivery
Subject: 3 new documents are ready to download

Your latest documents are available. Please retrieve them here:
View Your Documents — Secure File Portal

https://documents-portal.secure-file-share.ru/download/document-viewer-setup.exe

What the staff member sees looks official. What the link actually points to appears the moment you hover — and it’s neither the sender nor a document.

Reading a URL: the one rule that matters

You don’t need to be technical. To find out who really owns a web address, read the domain right-to-left and find the two parts just before the first single slash. That’s the real owner. Everything to the left of it is just a label the attacker can set to anything they like.

https://documents-portal.secure-file-share.ru/download/document-viewer-setup.exe
Looks familiar

documents-portal. — a subdomain the attacker invented to look trustworthy. Anyone can put a familiar-sounding word here. It means nothing.

The real owner

secure-file-share.ru — this is who the link actually belongs to. It’s not the sender you were expecting, and the .ru country code is a glaring red flag for an Australian business document.

The payload

.exe — the file is a program, not a document. Real documents end in .pdf, .docx or similar — never .exe, .msi, .scr or .zip containing one.

A padlock is not safety. The https:// and padlock icon only mean the connection is encrypted — not that the site is genuine. Attackers use HTTPS too.

Mitigation

How to shut this down in your organisation

Because there’s no malware to catch, defence here is about process, permissions and people rather than another scanner. These measures line up closely with the ASD Essential Eight, and together they remove almost every path these attacks rely on.

1Ban download portals

This is the big one. Stop accepting “click here to download your reports” workflows altogether. Genuine documents should arrive as real attachments you open and read — not as a link to some portal. If a supplier can only send via a portal, agree one known, verified address and treat everything else as suspect.

2Distrust every “download” link

The threat is the click-through, not the file type. Whether the link sits in an email or inside a PDF, a message whose job is to make you download and run something deserves suspicion — especially anything offering a “viewer”, “reader” or “secure downloader”.

3Teach hover-and-verify

Train every staff member to hover over links and read the real destination before clicking — and to stop and ask if the domain isn’t obviously right. Five minutes of this habit prevents the entire attack chain. PIP can run short awareness sessions for your team.

4Block unapproved remote tools

Use application control so only approved remote-access software can run — ideally just the tool your IT provider uses. If TeamViewer, AnyDesk or similar aren’t on your approved list, they should be blocked from installing or running at all.

5Remove local admin rights

Most users don’t need the ability to install software. Take away local administrator rights and a downloaded installer simply can’t take hold — the “it installed itself” problem largely disappears.

6Lock down shared mailboxes

Shared mailboxes multiply the damage — one lure, many victims. Limit who has access, make sure every member is trained, and never let a shared inbox be the place where nobody feels personally responsible for a suspicious message.

Layer on multi-factor authentication and email filtering that follows and checks links, and you’ve closed the door from several directions at once. PIP can put all of this in place and manage it for you as part of your cyber security.

If you suspect it’s happened

Don’t be shy — pick up the phone

If someone has clicked a suspicious link, downloaded something unexpected, or you’ve noticed your mouse moving on its own, unexpected software, or odd activity — act quickly and calmly. Speed matters far more than certainty. It is always better to call and be wrong than to wait and be right.

  1. Disconnect the machine from the network. Unplug the network cable or turn off Wi-Fi. This cuts the attacker’s access immediately while you get help.
  2. Leave it on, but stop using it. Don’t shut it down, and don’t try to uninstall anything or “clean” it — that can destroy the evidence we need to see how far they got and which other machines are involved.
  3. Ring PIP straight away. The sooner we’re on it, the sooner we can contain it, check every affected device (remember, shared mailboxes spread this), and lock the attacker out for good.
Think you’ve been compromised? Call now.Our Sydney team can start containing it immediately.
(02) 9488 7655
FAQ

Common questions

Is this a virus?
Usually not in the traditional sense. There is often no malicious code for antivirus to find. Instead, a staff member is tricked into installing legitimate remote-access software — such as TeamViewer or AnyDesk — and the attacker then uses that genuine, trusted tool to control the machine. Because the software is real and signed, antivirus lets it run.
Why didn’t our antivirus or PIP’s monitoring stop it?
Because nothing technically malicious was installed. Antivirus and endpoint monitoring are built to spot malware, and a signed, legitimate remote-access tool is not malware, so no alert fires. The compromise happens through a legitimate channel — which is exactly why these attacks are so effective and so hard to see.
Are PDFs safe to open?
Opening a PDF simply to read it is generally low-risk. The danger is a PDF — or an email — whose real purpose is to get you to click a link and download something. If a document asks you to click through to a portal to view or download it, treat that click as the threat, not the PDF itself.
I think someone clicked something — what should we do?
Disconnect the device from the network — unplug the network cable or turn off Wi-Fi — stop using it, and call PIP immediately on (02) 9488 7655. Do not try to uninstall or clean it yourself, as that can destroy the evidence we need to see how far the attacker got and which other machines are affected.
Managed cyber security

Close the door these attacks walk through

Application control, admin-rights hardening, mailbox lockdown, link-checking email filtering and staff awareness — PIP puts the whole picture in place and manages it, so a single click can’t hand your business away.

Explore PIP cyber security Or talk to our team →
Scroll to Top