Insights: RMM Tools | Huntress Blog
ID: ae21f16f-e28b-5c8b-8e19-96a08ad21104
STIX ID: report--ae21f16f-e28b-5c8b-8e19-96a08ad21104
Feed Name: Huntress Blog
Huntress warns that threat actors are leveraging legitimately installed remote-access/RMM tools (especially TeamViewer) via compromised credentials to maintain persistence in SMB environments. Incidents observed include attempted ransomware deployment and XMRig miner installation, often limited to the accessed endpoints without extensive lateral movement; Huntress advises accurate asset/application inventories and reviewing TeamViewer 'connections_incoming.txt' logs to detect unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
