logo

How Threat Actors Abuse Remote Management Software for Initial Access

ID: 26b20ed5-e12d-581a-8e8d-a79e068d5c75

STIX ID: report--26b20ed5-e12d-581a-8e8d-a79e068d5c75

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-04-28

...
...

This report details widespread, active abuse of legitimate RMM and deployment tooling—particularly daisy-chaining RMMs like ScreenConnect via MSI installers and phishing lures—to establish persistent remote access, harvest credentials, and exfiltrate sensitive data; it includes observed operational workflows, hosted phishing infrastructure on GitHub, sample IOCs (hashes, filenames, IPs), and recommendations to treat RMM deployments as security-relevant events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.