Remote monitoring and management (RMM) platforms are the backbone of every slot online operation, and that’s exactly why attackers love them.
Threat actors are increasingly hijacking legitimate RMM agents inside client environments rather than building custom malware. Next, hackers are using them as a unified control hub for command-and-control, lateral movement, and ransomware deployment. Meanwhile, the use of traditional hacking tools plummeted by 53% as cybercriminals built entire playbooks around RMM tools to drop malware, steal credentials and execute commands.
The Huntress 2026 Cyber Threat Report recorded a 277% jump in RMM abuse during 2025, and RMM abuse now accounts for 24% of all incidents the company observed.
Other vendors reported similar patterns: 30% of the security incidents Blackpoint Cyber responded to involved abusing RMM software, with CAPTCHA and ClickFix scams driving 58% of malicious activity detected.
Separately, RMM tool abuse was the single biggest endpoint threat in one analysis, accounting for 26% of all detections, with tools such as ScreenConnect, AteraAgent and MeshAgent used to gain unauthorised access.
The risk to MSPs is amplified by their structure: one compromised RMM instance can mean access to dozens of downstream clients simultaneously. When attackers compromise an RMM solution managed by an MSP, they can immediately access multiple downstream customers in a massive supply chain attack.
A recent real-world example bore this out when an attack on an MSP led to the mass isolation of 78 businesses and subsequent exploitation across four downstream customers.
Leave a Reply