A Series of Unfortunate (RMM) Events
ID: d6a40814-94fb-54b9-bde0-da42a32461fd
STIX ID: report--d6a40814-94fb-54b9-bde0-da42a32461fd
Feed Name: Huntress Blog
Huntress SOC observed a series of active campaigns in which attackers use phishing lures to deliver and then chain multiple remote monitoring and management (RMM) tools—both legitimate and renamed/rogue instances—to establish persistence and operational access (examples include GoTo Resolve, PDQ, ScreenConnect, SimpleHelp, and ITarian). The report documents several case studies, execution paths, attacker-controlled domains and download sources as IoCs, and recommends defenses such as asset inventory, RMM auditing, application controls, and log monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
