logo

Cato CTRL™ Threat Research: Investigation of RMM Tools Leveraged by Ransomware Gangs in Real-World Incidents 

ID: 8f181719-d49e-5d41-8001-9029bf20205a

STIX ID: report--8f181719-d49e-5d41-8001-9029bf20205a

Feed Name: Cato Networks

Threat Score
75/100

Date Published: 2025-07-21

Date Updated: 2026-07-23

Author: Guy Waizel

...
...

This report examines multiple 2024–2025 incidents where ransomware gangs leveraged legitimate Remote Monitoring and Management (RMM) tools—including AnyDesk, ScreenConnect, PDQ Deploy, and SimpleHelp—to gain initial access, maintain persistence, move laterally, and exfiltrate data. It summarizes three real-world cases (UK and US victims), describes an RMM PoC via phishing, shows network detection examples (Wireshark/Cato XDR), and provides operational recommendations (allowlisting, privilege limitation, monitoring, and auditing) to detect and mitigate RMM-based abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.