logo

Remote Monitoring and Management Tools: A Gateway for Bulk Attacks on MSP Customers

ID: ed0aa6e0-8853-5612-b46b-b8f6a3041032

STIX ID: report--ed0aa6e0-8853-5612-b46b-b8f6a3041032

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-07-02

Date Updated: 2026-04-28

...
...

Huntress reports on a series of incidents where an attacker compromised an MSP's Atera RMM instance, used the SYSTEM account to execute net.exe to add local admin users (e.g., msoit, se91, veean, vnaee with similar passwords), and installed Cloudflared tunnels with the same token across three customer environments; process lineage traced back to AteraAgent.exe. The SOC isolated impacted endpoints, advised shutting down the RMM, rotating credentials, and removing created accounts; the report contextualizes RMM abuse risk (citing the 2021 Kaseya supply-chain impact) and provides mitigation guidance for MSPs and customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.