RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress

Imported from official source

Cybersecurity Classified by Officially

RMM abuse jumped 277% last year because attackers use trusted remote access tools to blend into normal IT activity. Huntress Tactical Response now sees it in nearly 40% of the incidents it investigates.

A rogue RMM install can sit quietly for months before an attacker uses it. One ScreenConnect install went unused for five months, then led to browser access, malicious inbox rules, and spam sent from the victim's own account.

Finding an RMM tool isn't enough. Approved and rogue installs can look identical in process and network telemetry, so defenders need to inventory what's installed and decide which tools belong on each machine. RMM Guard is a new Huntress application-control capability that helps with this.

Remote monitoring and management (RMM) tools keep modern IT moving. They let teams access, monitor, and troubleshoot devices from anywhere. But the same trusted access that makes support easier can give an attacker a stealthy path into your environment.

Attackers don't need to sneak malware past your defenses when they can abuse software your organization already trusts. That's the problem Dray Agha, Senior Manager of Tactical Response at Huntress, and Matt Caldwell, Director of Fraud Prevention at AnyDesk, unpacked during the Trusted Tools in Untrusted Hands: RMM Abuse Hiding in Plain Sight live event: why attackers are ditching their own malware for legitimate tools, how that abuse unfolds, and how organizations can shut it down.

Why attackers prefer your RMM to their own malware

Remote access tool abuse climbed 277% last year, according to the Huntress 2026 Cyber Threat Report. On top of that, our Security Operations Center (SOC) Tactical Response team now sees this tactic in almost 40% of the incidents we investigate.

From an attacker's POV, there are many pros to abusing trusted tools like RMM: 

Writing your own malware means building command-and-control from scratch and babysitting it forever. A signed, vendor-hosted RMM shows up with all of that done.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/rmm-abuse-trusted-tools-untrusted-hands

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/rmm-abuse-trusted-tools-untrusted-hands

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.