RMM Abuse Explodes as Hackers Ditch Malware
ID: 3d13be28-e4b0-5d92-83e5-3c0bd81acf7f
STIX ID: report--3d13be28-e4b0-5d92-83e5-3c0bd81acf7f
Feed Name: Dark Reading
Huntress's 2026 Cyber Threat Report finds a massive (277% YoY) increase in abuse of remote monitoring and management (RMM) tools across industries, with attackers using RMM as stealthy C2 and persistence platforms rather than traditional malware. The report names commonly abused products (ScreenConnect, AnyDesk, Atera, NetSupport, PDQ Connect, SplashTop), highlights sector impacts (healthcare, technology), describes post-compromise tradecraft and product-specific uses, and recommends vendor and defender mitigations such as tighter controls, telemetry, and allowlists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
