A credential-free-looking install flow can turn a legitimate remote support product into an attacker-controlled foothold, with the session blending into normal IT activity.