RMM Tools for MSPs: Features, Risks & How to Stay Secure
Cybersecurity Classified by Officially
Remote Monitoring Management (RMM) tools are the backbone of how MSPs operate. They're how you patch hundreds of endpoints without burning a weekend, how you troubleshoot a client's issue at 2am without driving across town, and how you keep dozens of client environments running without losing your mind.
But here's the part that doesn't always make it into the vendor brochure: the same access that makes RMM tools indispensable to you makes them irresistible to threat actors
When threat actors compromise an MSP’s RMM instance, it allows them to cast a wide net across the MSP’s downstream customer base, effectively hitting multiple organizations through one attack. That’s because once threat actors compromise the MSP’s RMM instance, they then have direct access to the MSP’s entire customer base.
The community saw this play out during the infamous 2021 Kaseya VSA supply chain attack. The ransomware attack impacted between 50 and 60 MSPs and resellers, but the brunt of the impact was felt most directly by their customers, which totaled between 1,500 to 2,000 organizations.
It’s been four years since the Kaseya attack, but Huntress continues to see threat actors compromise RMMs in MSP environments to hit multiple customers. Huntress’ Security Operations Center (SOC) analysts recently saw an incident in June, where a threat actor compromised an MSP’s RMM instance, effectively using that instance to target three of its customers before the Huntress SOC was able to isolate the impacted endpoint and work with the partner to remediate the attack.
In this first of a two-part series, we'll go over this incident. Stay tuned for the second part, where we'll dive into a similar incident that we saw.
One RMM compromise, three businesses hit
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/remote-monitoring-management-tools-gateway-for-attacks-on-msp-pt-1
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/remote-monitoring-management-tools-gateway-for-attacks-on...