A fake business document and a trusted support app can be enough to create durable access, especially when defenders do not tightly govern remote software.