Scam alert · 4 minute read

Scammers' newest trick: fake documents that quietly let them in

For years, remote-access scams started with a phone call. Increasingly, they start with an email attachment or a download instead — and the victim never hears a voice at all. Here's how the new trick works, how to spot it, and what we've just changed in RemoteShield to stop it.

The old way: a phone call

You probably know the classic version. Someone phones pretending to be your bank, your internet provider or Microsoft, says there's a problem, and talks you into installing a program so they can "fix" it. That program lets them see and control your screen. If you're not sure how these scams usually unfold, our plain-language guide walks through it step by step.

The new way: a file you didn't expect

This year, security researchers have been tracking scams that skip the phone call entirely:

  • Fake documents. An email arrives with what looks like a tax form, an invoice or a "secure document" to open. Opening it quietly installs a remote-control program. One campaign using this trick ran from January to at least July 2026 across dozens of countries.
  • Fake "desktop apps". A convincing website offers a downloadable app for a service you already use. The service has never had an app. What gets installed is remote-control software, set up so it shows no warning banner, no icon and no pop-up — the person using the computer has no idea anyone else can connect.

The clever — and worrying — part is that the programs being installed are real, legitimate business tools. IT departments use them every day. Because they aren't "viruses", antivirus software often doesn't flag them. One security firm reported that criminals' use of these tools rose by more than 270% in a single year.

What we've changed

RemoteShield doesn't care how a remote-control program got onto your computer — a phone call, a fake document or a fake app. If it's a program on our list, it's stopped the moment it starts.

In this month's update we added 33 more programs, bringing the total to 341. They include:

  • the hidden background version of a popular remote-support tool — the exact version used in the fake-app scam above;
  • several parts of another remote-support tool used in the fake-document campaign;
  • "support software" that is actually malware in disguise;
  • around twenty lesser-known remote-control and remote-management tools.

We were just as careful about what we didn't add. Some of these tools share file names with genuine parts of Windows, so we left those out — protection shouldn't break your computer.

If you already use RemoteShield, there's nothing you need to do. The update arrives automatically.

Three habits that protect you

  1. 1

    Don't open files you weren't expecting — even if they look like an invoice or a tax form from a company you know. If in doubt, contact the company using a phone number or website you already trust, not the one in the email.

  2. 2

    Only download apps from the company's official website or app store. If a service you use has never offered a computer app before, a "new faster app" is a red flag.

  3. 3

    Never let anyone who contacted you connect to your computer. Real banks, phone companies and tech companies will never ask. If someone does — hang up.

Think something is happening right now? Here's exactly what to do.

Not protected yet?

RemoteShield is a small Windows program that blocks the remote-control software scammers rely on — however it got onto the computer. It runs quietly in the background, and it's a thoughtful thing to set up for a parent or grandparent.

Try it free for 30 days