logo

Uptick in Bomgar RMM Exploitation

ID: accba24c-a6f8-5e57-be2d-8060c67f2948

STIX ID: report--accba24c-a6f8-5e57-be2d-8060c67f2948

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-28

...
...

Huntress SOC observed an uptick in active exploitation of vulnerable BeyondTrust/Bomgar RMM (CVE-2026-1731) from February through April 2026 where attackers leveraged compromised RMM instances—particularly those of MSPs and service providers—to perform account compromise and privilege escalation, deploy additional remote management tools (AnyDesk, Atera, ScreenConnect), and deliver LockBit ransomware to multiple downstream organizations; the report provides timelines, TTPs, IOCs (hashes, IPs, email, driver names), and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.