Uptick in Bomgar RMM Exploitation
ID: accba24c-a6f8-5e57-be2d-8060c67f2948
STIX ID: report--accba24c-a6f8-5e57-be2d-8060c67f2948
Feed Name: Huntress Blog
Huntress SOC observed an uptick in active exploitation of vulnerable BeyondTrust/Bomgar RMM (CVE-2026-1731) from February through April 2026 where attackers leveraged compromised RMM instances—particularly those of MSPs and service providers—to perform account compromise and privilege escalation, deploy additional remote management tools (AnyDesk, Atera, ScreenConnect), and deliver LockBit ransomware to multiple downstream organizations; the report provides timelines, TTPs, IOCs (hashes, IPs, email, driver names), and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
