logo

The remote access blind spot: An analysis of RMM tool risk for SMBs

ID: 3a79f7d3-390f-51f9-a749-74460c52156f

STIX ID: report--3a79f7d3-390f-51f9-a749-74460c52156f

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-07-24

...
...

Acronis telemetry analysis of 1.8M endpoints (Jan 2025–Mar 2026) shows widespread RMM/tool sprawl—63% of endpoints run two or more remote access tools—creating a large attack surface that threat actors increasingly exploit by installing legitimate, open-source, or leaked RMM tools (notably MeshAgent and Ammyy) to blend in with normal admin traffic; the report highlights high-impact vulnerabilities disclosed in RMM products, frequent RDP use in intrusions, campaign-driven spikes in incidents, and the disproportionate presence of certain tools in malicious activity versus legitimate usage, with follow-up guidance promised in part two.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.