logo

Why ransomware gangs love using RMM tools—and how to stop them

ID: 01d2afc7-6497-5af1-a39c-ebb1719ac97b

STIX ID: report--01d2afc7-6497-5af1-a39c-ebb1719ac97b

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-02-22

Date Updated: 2026-04-28

...
...

Ransomware gangs are increasingly abusing legitimate Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, Atera, Splashtop) via stolen/weak credentials, post-compromise installs, or social engineering to gain access, persist, and stage encryption/data theft; the report lists commonly abused RMM products and actors, provides example incidents (unpatched servers leading to RMM installs and AnyDesk used for C2), and recommends blocking non-essential RMM applications and deploying EDR/MDR to detect and contain misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.