PDQ Deploy is a Windows-based software deployment tool used by IT administrators to remotely install software, patches, and scripts across endpoints.
Overview
PDQ Deploy is a Windows-based software deployment tool used by IT administrators to remotely install software, patches, and scripts across endpoints. In recent cybercrime activity, threat actors have abused legitimate RMM/deployment tooling to remotely distribute ransomware such as Medusa and DragonForce, illustrating how trusted admin tools can be repurposed for cyber attacks. This trend underscores the risk of tool abuse and the need for monitoring, access controls, and defense-in-depth around deployment platforms.
Related Threat Clusters
-
Akira Ransomware Uses Safe Mode to Evade EDR Detection
In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall…
11 articles · Updated August 12, 2026 -
Medusa and DragonForce Ransomware Exploit RMM Tools in 2025 UK Attacks
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
9 articles · Updated November 11, 2025 -
Ransomware Groups Medusa and DragonForce Exploit RMM Tools in 2025 Attacks
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. They leveraged three critical vulnerabilities…
3 articles · Updated November 11, 2025
Recent Intelligence Reports
- AvosLocker — www.sophos.com · August 12, 2026
- Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware — Cybersecuritynews · November 11, 2025