Cato CTRL™ Threat Research: Investigation of RMM Tools Leveraged by Ransomware Gangs in Real-World Incidents
ID: 8f181719-d49e-5d41-8001-9029bf20205a
STIX ID: report--8f181719-d49e-5d41-8001-9029bf20205a
Feed Name: Cato Networks
This report examines multiple 2024–2025 incidents where ransomware gangs leveraged legitimate Remote Monitoring and Management (RMM) tools—including AnyDesk, ScreenConnect, PDQ Deploy, and SimpleHelp—to gain initial access, maintain persistence, move laterally, and exfiltrate data. It summarizes three real-world cases (UK and US victims), describes an RMM PoC via phishing, shows network detection examples (Wireshark/Cato XDR), and provides operational recommendations (allowlisting, privilege limitation, monitoring, and auditing) to detect and mitigate RMM-based abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
