logo

Tales of Too Many RMMs

ID: 1a563c69-6d31-5f8c-b50e-c547eb65cb56

STIX ID: report--1a563c69-6d31-5f8c-b50e-c547eb65cb56

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-04-17

Date Updated: 2026-04-28

...
...

This Huntress report describes multiple real incidents in which threat actors exploited legacy RMM and unsecured remote access (including RDP without MFA) to install additional RMM tools, exfiltrate credentials, and deploy ransomware (notably Akira), highlighting the complexity of detecting abuse when multiple remote access tools are present and stressing the need for accurate asset inventories, attack-surface reduction, and full EDR coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.