How Threat Actors Abuse Remote Management Software for Initial Access
ID: 26b20ed5-e12d-581a-8e8d-a79e068d5c75
STIX ID: report--26b20ed5-e12d-581a-8e8d-a79e068d5c75
Feed Name: Huntress Blog
Threat Score
This report details widespread, active abuse of legitimate RMM and deployment tooling—particularly daisy-chaining RMMs like ScreenConnect via MSI installers and phishing lures—to establish persistent remote access, harvest credentials, and exfiltrate sensitive data; it includes observed operational workflows, hosted phishing infrastructure on GitHub, sample IOCs (hashes, filenames, IPs), and recommendations to treat RMM deployments as security-relevant events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
