Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
Cybersecurity Classified by Officially
Phishing can install more than malware. A convincing document lure can give attackers hands-on access through a legitimate RMM tool.
One rogue RMM often leads to another. Attackers stack remote-access clients so they retain a backup path if the first installation is found and removed.
Trusted software makes detection harder. A rogue install can use legitimate vendor infrastructure and look similar to the approved tools IT teams rely on every day.
Full remediation starts with visibility. Teams should have an inventory of approved RMM tools and investigate the context behind every install, connection, and user activity.
Attackers are increasingly turning to trusted software your business already depends on instead of custom malware or exploits.
In one recent Huntress Security Operations Center (SOC) investigation, a secure-document lure hid the installation of a remote monitoring and management (RMM) tool. The employee didn't know the file they opened would lead to an attacker's successful intrusion, ultimately installing a rogue ITarian client, followed by a ScreenConnect session for persistent access.
In two others, the phishing emails mentioned ScreenConnect by name. But the victim expected to view a document, not install an attacker-controlled persistent remote access client.
Across all three incidents our SOC investigated, phishing opened the door to malicious remote access via the same trusted RMM tools your IT team likely uses to support your organization's devices. Once the attackers gained initial access, they quickly added more rogue RMM clients to create redundant and persistent paths back in.
Phishing isn't just about stolen credentials anymore
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 24, 2026 08:00
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access