logo

RMM Abuse Explodes as Hackers Ditch Malware

ID: 3d13be28-e4b0-5d92-83e5-3c0bd81acf7f

STIX ID: report--3d13be28-e4b0-5d92-83e5-3c0bd81acf7f

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-02-17

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Huntress's 2026 Cyber Threat Report finds a massive (277% YoY) increase in abuse of remote monitoring and management (RMM) tools across industries, with attackers using RMM as stealthy C2 and persistence platforms rather than traditional malware. The report names commonly abused products (ScreenConnect, AnyDesk, Atera, NetSupport, PDQ Connect, SplashTop), highlights sector impacts (healthcare, technology), describes post-compromise tradecraft and product-specific uses, and recommends vendor and defender mitigations such as tighter controls, telemetry, and allowlists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.