The dual-use dilemma: Rethinking detection for remote access tool abuse
ID: 647a69ee-5252-57cc-baa9-be5bb9e6f2fc
STIX ID: report--647a69ee-5252-57cc-baa9-be5bb9e6f2fc
Feed Name: Red Canary
Threat Score
This report analyzes a surge in adversary abuse of legitimate Remote Monitoring and Management (RMM) tools—detailing how attackers use signed installers, chained RMMs, MSI sideloading, and deceptive lures to gain persistence and evade detections—and provides tool-specific detection guidance (NetSupport, SimpleHelp, PDQ Connect, RemotePC, Syncro, Atera, ITarian, ScreenConnect, QuickAssist/HopToDesk) and strategic recommendations for SecOps teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
