Hidden entry points
Phishing, exposed RDP, stolen credentials, and vulnerable internet-facing systems give attackers a foothold. From there, legitimate administrative and remote-access tools can help them move without looking like a traditional malware outbreak.