Rogue RMM Abuse: How Attackers Exploit Remote Access Tools

Imported from official source

Cybersecurity Classified by Officially

Phishing can install more than malware. A convincing document lure can give attackers hands-on access through a legitimate RMM tool.

One rogue RMM often leads to another. Attackers stack remote-access clients so they retain a backup path if the first installation is found and removed.

Trusted software makes detection harder. A rogue install can use legitimate vendor infrastructure and look similar to the approved tools IT teams rely on every day.

Full remediation starts with visibility. Teams should have an inventory of approved RMM tools and investigate the context behind every install, connection, and user activity.

Attackers are increasingly turning to trusted software your business already depends on instead of custom malware or exploits. 

In one recent Huntress Security Operations Center (SOC) investigation, a secure-document lure hid the installation of a remote monitoring and management (RMM) tool. The employee didn't know the file they opened would lead to an attacker's successful intrusion, ultimately installing a rogue ITarian client, followed by a ScreenConnect session for persistent access. 

In two others, the phishing emails mentioned ScreenConnect by name. But the victim expected to view a document, not install an attacker-controlled persistent remote access client. 

Across all three incidents our SOC investigated, phishing opened the door to malicious remote access via the same trusted RMM tools your IT team likely uses to support your organization's devices. Once the attackers gained initial access, they quickly added more rogue RMM clients to create redundant and persistent paths back in. 

Phishing isn't just about stolen credentials anymore

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 24, 2026 08:00
Versions
1 recorded
Identity
https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.