logo

Your Screen Is Being Monitored: Initial Access via RMM Tools

ID: 31002898-b97d-55f6-9ca4-8929f47665de

STIX ID: report--31002898-b97d-55f6-9ca4-8929f47665de

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-04-29

...
...

ReliaQuest reports that cybercriminals are increasingly abusing legitimate RMM tools (e.g., Atera, Splashtop, AnyDesk, ConnectWise/ScreenConnect, TeamViewer, ngrok, Netsupport) to bypass defenses, maintain persistent remote access, and enable ransomware/data exfiltration. The report provides observed host and network artifacts (process/service names and domains), cites actor usage (including Qbot, Scattered Spider, Black Basta, Conti), and recommends blocking unauthorized RMM network domains, implementing application allowlisting (GPO/SRP), and deploying detection/hunting rules to identify misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.