Your Screen Is Being Monitored: Initial Access via RMM Tools
ID: 31002898-b97d-55f6-9ca4-8929f47665de
STIX ID: report--31002898-b97d-55f6-9ca4-8929f47665de
Feed Name: ReliaQuest Blog
ReliaQuest reports that cybercriminals are increasingly abusing legitimate RMM tools (e.g., Atera, Splashtop, AnyDesk, ConnectWise/ScreenConnect, TeamViewer, ngrok, Netsupport) to bypass defenses, maintain persistent remote access, and enable ransomware/data exfiltration. The report provides observed host and network artifacts (process/service names and domains), cites actor usage (including Qbot, Scattered Spider, Black Basta, Conti), and recommends blocking unauthorized RMM network domains, implementing application allowlisting (GPO/SRP), and deploying detection/hunting rules to identify misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
