Remote Monitoring and Management Tools: A Gateway for Bulk Attacks on MSP Customers
ID: ed0aa6e0-8853-5612-b46b-b8f6a3041032
STIX ID: report--ed0aa6e0-8853-5612-b46b-b8f6a3041032
Feed Name: Huntress Blog
Huntress reports on a series of incidents where an attacker compromised an MSP's Atera RMM instance, used the SYSTEM account to execute net.exe to add local admin users (e.g., msoit, se91, veean, vnaee with similar passwords), and installed Cloudflared tunnels with the same token across three customer environments; process lineage traced back to AteraAgent.exe. The SOC isolated impacted endpoints, advised shutting down the RMM, rotating credentials, and removing created accounts; the report contextualizes RMM abuse risk (citing the 2021 Kaseya supply-chain impact) and provides mitigation guidance for MSPs and customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
