Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
Huntress, Wednesday, September 23rd, 2026
Huntress warns attackers use phishing lures to install rogue remote monitoring and management tools, often stacking multiple RMMs for backup access.
Huntress describes how phishing lures, including convincing document attachments, are being used to install legitimate remote monitoring and management (RMM) tools for hands-on attacker access rather than custom malware.
Attackers often stack multiple rogue RMM installations so they retain a backup access path if the first is discovered and removed.
Because these tools are legitimate vendor software, they can closely resemble the approved RMM tools IT teams already use, making detection harder.
Huntress recommends maintaining an inventory of approved RMM tools and investigating the context behind every install, connection, and user activity.