
27.07.2026 rmm-abuseransomwareliving-off-the-landincident-response
Remote Monitoring and Management (RMM) tools such as ScreenConnect, Atera, Splashtop, or AnyDesk are everyday infrastructure for IT departments and managed service providers alike. That very ubiquity is exactly what makes them attractive to attackers. The Huntress 2026 Cyber Threat Report recorded a staggering 277% jump in RMM abuse in 2025. Arctic Wolf confirms the trend from another angle: 59.4% of ransomware cases investigated by Arctic Wolf Incident Response began with external remote access – a category that includes RMM abuse or exploitation – and the firm observed malicious usage of 32 different RMM tools in a single quarter. Acronis TRU adds that more than 51 RMM solutions were identified as potential attack vectors, with Splashtop, ConnectWise, ScreenConnect, and Atera repeatedly abused in real-world intrusions.
The forensic problem is baked into the tools’ design itself. As one analysis puts it, standard tools detect known bad signatures like ransomware or remote access trojans, but a legitimate RMM executable simply does not fit that profile, so it slips through while appearing to be routine IT activity. Huntress researchers found that over 50% of cases involving suspicious Atera RMM activity were directly tied to ransomware attacks.
Initial access almost always starts with social engineering. Huntress describes typical lures as emails that look authentic — think DocuSign request, a party invitation, or a Dropbox link. Increasingly, attackers also repurpose legitimate tunneling infrastructure for delivery. Researchers at Securonix and Sekoia have documented campaigns in which threat actors leverage Cloudflare’s tunneling service — specifically the trycloudflare.com subdomain — to host and deliver malicious payloads, even though the service is commonly used by developers for temporarily exposing local servers without modifying firewall rules or setting up static infrastructure. GuidePoint Security notes why cloudflared is particularly appealing to attackers: it allows a threat actor to configure an environment in advance of an attack, then execute a single command from a victim machine to establish a foothold, all without exposing their configurations on the victim machine prior to a successful tunnel connection.
Once an RMM tool is deployed, the attacker inherits its full capability set. As Huntress warns, attackers inherit that persistence — suddenly they can automate tasks, move laterally across the network, execute commands, and even drop ransomware, all while appearing to be a helpful IT administrator. The speed of escalation is striking: when tools like RustDesk or Atera are abused, ransomware damage can unfold in as little as one to two hours.
For incident responders, this means signature-based malware hunting alone is no longer sufficient. Cato Networks captures the core dilemma: this dual-use nature of RMM tools presents a growing challenge for organizations, where the line between authorized administrative activity and malicious behavior is increasingly difficult to define and detect. Acronis flags an additional supply-chain angle: targeting an MSP’s RMM infrastructure enables adversaries to pivot into multiple client environments simultaneously, amplifying the blast radius and monetization potential of a single intrusion.
Huntress recommends proactive environment fingerprinting as the practical countermeasure: it’s not enough to know that you “use ScreenConnect” — you need an ongoing, detailed inventory of your attack surface that answers questions like what specific RMM tools are approved, what hashes those tools should carry, and what URLs or IP addresses they should connect to. GovInfoSecurity’s coverage of the same trend adds concrete IR playbook actions: integrate RMM into the incident response playbook, simulate attacks through purple team exercises, move beyond signature-based alerts toward behavioral baselining, and integrate SIEM with RMM logs for anomaly detection.
In practice, this translates into systematically correlating installer artifacts, Windows event logs — particularly service installations and scheduled tasks — outbound connections to known RMM or tunnel endpoints, and deviations from an approved-hash allowlist. Because by the time an “IT session” turns into a full-blown encryption event, the investigative window has already closed to a matter of hours.
← Back to overview