Remote Monitoring and Management Tools: A Gateway for Bulk Attacks on MSP Customers, Pt. 2
ID: 1d41eb87-d0e8-5eb2-a7f9-0441b50cac05
STIX ID: report--1d41eb87-d0e8-5eb2-a7f9-0441b50cac05
Feed Name: Huntress Blog
Threat Score
Huntress investigated multiple incidents in June–July where threat actors compromised an MSP's Atera RMM to install Cloudflare tunnels, create accounts, disable Defender, and deploy Akira ransomware across MSP and customer endpoints; analysts used endpoint and RMM logs to correlate identical TTPs and IOCs across attacks and the SOC rapidly isolated affected systems to limit impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
