Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Huntress

Rogue RMM Abuse: How Attackers Exploit Remote Access Tools

Huntress, Wednesday, September 23rd, 2026

Huntress warns attackers use phishing lures to install rogue remote monitoring and management tools, often stacking multiple RMMs for backup access.

Huntress describes how phishing lures, including convincing document attachments, are being used to install legitimate remote monitoring and management (RMM) tools for hands-on attacker access rather than custom malware.

Attackers often stack multiple rogue RMM installations so they retain a backup access path if the first is discovered and removed.

Because these tools are legitimate vendor software, they can closely resemble the approved RMM tools IT teams already use, making detection harder.

Huntress recommends maintaining an inventory of approved RMM tools and investigating the context behind every install, connection, and user activity.

more →  ·  More from Huntress →