Attackers Exploit Legitimate RMM Tools in 45% of Endpoint Incidents, Gaining Persistent Access
What Happened — Huntress reported that 45 % of endpoint‑related incidents in Q1 2026 involved abuse of legitimate remote‑monitoring‑and‑management (RMM) software. Attackers install or hijack tools such as Tiflux, UltraVNC, Splashtop, or ScreenConnect, then use them for persistent remote command execution that appears as routine admin activity. The tactic grew 277 % year‑over‑year in 2025 and is now a common precursor to ransomware or data theft.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs must maintain an up‑to‑date inventory of approved third‑party tools and evidence that only those tools are present on endpoints.
- Unauthorized RMM installations bypass traditional logging and can hide malicious activity, eroding the defensible audit trail required for compliance reviews.
- Demonstrating vendor‑tool oversight through automated monitoring aligns with the control objective of “third‑party software approval and continuous verification.”
Who Is Affected — Managed Service Providers, internal IT teams, and any organization that relies on RMM solutions across sectors such as technology SaaS, finance, healthcare, and manufacturing.
Recommended Actions
- Create and enforce a formal RMM approval policy; require documented business justification for each tool.
- Deploy continuous endpoint monitoring that flags any unapproved RMM binaries or services and generates immutable evidence.
- Integrate the findings into your third‑party risk management workflow and retain logs for audit readiness.
Technical Notes — Attackers deliver fake service‑agreement documents to trick users into installing RMM agents, then layer additional remote‑control utilities. AI‑generated phishing lures accelerate the initial compromise. Once installed, the RMM tool provides persistent access and can be used to harvest session tokens, bypassing MFA. Source: Help Net Security