logo

Insights: RMM Tools | Huntress Blog

ID: ae21f16f-e28b-5c8b-8e19-96a08ad21104

STIX ID: report--ae21f16f-e28b-5c8b-8e19-96a08ad21104

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-04-02

Date Updated: 2026-04-28

...
...

Huntress warns that threat actors are leveraging legitimately installed remote-access/RMM tools (especially TeamViewer) via compromised credentials to maintain persistence in SMB environments. Incidents observed include attempted ransomware deployment and XMRig miner installation, often limited to the accessed endpoints without extensive lateral movement; Huntress advises accurate asset/application inventories and reviewing TeamViewer 'connections_incoming.txt' logs to detect unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.