Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Phishing Campaigns Abuse RMM Tools to Maintain Persistent Access

Microsoft researchers report that threat actors are using phishing to steal credentials and then leverage Remote Monitoring and Management (RMM) platforms to sustain footholds across victim environments. The tactic underscores the need for robust identity controls and continuous monitoring of privileged remote tools for audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 microsoft.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
microsoft.com

Phishing Campaigns Abuse RMM Tools to Maintain Persistent Access

What Happened — Microsoft security researchers identified a wave of phishing emails that harvest credentials for Remote Monitoring and Management (RMM) platforms. Compromised accounts are then used to install RMM agents, giving attackers low‑profile, long‑term access to endpoints and enabling lateral movement across victim networks.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of privileged account activity is a core control‑objective that a control‑assurance program must capture.
  • Evidence of RMM usage, combined with identity‑access logs, provides a defensible audit trail for frameworks such as NIST CSF 2.0.
  • Robust phishing awareness and MFA reduce the likelihood of credential compromise that fuels these persistent‑access attacks.

Who Is Affected — Managed Service Providers (MSPs) and enterprises that rely on RMM solutions across technology, SaaS, and cloud‑infrastructure sectors.

Recommended Actions

  • Enforce multi‑factor authentication and strong password policies for all RMM accounts.
  • Deploy continuous logging and real‑time monitoring of RMM agent activity.
  • Conduct regular security‑awareness training focused on phishing detection.

Source: Microsoft Security Blog

Technical Notes — Attack vector: phishing emails delivering credential‑stealing pages or malicious attachments. Threat actors exploit the trust relationship inherent in RMM tools to gain persistent footholds. No specific CVE is involved; the risk stems from credential abuse and inadequate monitoring. Source: same as above

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →