Why ransomware gangs love using RMM tools—and how to stop them
ID: 01d2afc7-6497-5af1-a39c-ebb1719ac97b
STIX ID: report--01d2afc7-6497-5af1-a39c-ebb1719ac97b
Feed Name: Malwarebytes Blog
Ransomware gangs are increasingly abusing legitimate Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, Atera, Splashtop) via stolen/weak credentials, post-compromise installs, or social engineering to gain access, persist, and stage encryption/data theft; the report lists commonly abused RMM products and actors, provides example incidents (unpatched servers leading to RMM installs and AnyDesk used for C2), and recommends blocking non-essential RMM applications and deploying EDR/MDR to detect and contain misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
