Abuse of RMM Tools in Phishing Attacks Skyrockets

Phishing Attacks Abusing Legitimate RMM Tools Surge by 475%

HIGH
October 8, 2026
6m read
PhishingCyberattackMalware

Related Entities

Organizations

Fortra HuntressCISA

Products & Tech

Full Report

Executive Summary

Security researchers are reporting a dramatic surge in phishing attacks that abuse legitimate Remote Monitoring and Management (RMM) software. A report from Fortra indicates a 475% increase in such attacks in the first nine months of 2026 compared to the entirety of 2025. These campaigns primarily target North American financial institutions and rely on social engineering to trick victims into granting attackers remote access to their systems using trusted tools like ScreenConnect and AnyDesk. This 'living off the land' technique bypasses traditional malware detection by using legitimate software for malicious purposes. The use of portable executables allows these tools to run without administrative privileges, further complicating detection and prevention efforts.

Threat Overview

The core of this threat is social engineering. Attackers contact victims, often posing as technical support or a trusted entity, and convince them to install and authorize a legitimate RMM tool. Once granted access, the attacker has full control over the victim's machine, enabling them to steal data, install further malware, or conduct financial fraud.

A specific campaign analyzed by security firm Huntress demonstrates the evolving sophistication of these attacks. First seen on September 10, 2026, this campaign abused Microsoft Power BI domains to add a layer of legitimacy to the initial lure.

Attack Chain

  1. Lure: The victim receives a phishing email containing a link to a page hosted on a legitimate powerbi.com domain.
  2. Redirection: The Power BI page contains a fake document that, when clicked, opens a new tab leading to an attacker-controlled website.
  3. Evasion: The attacker's website fingerprints the victim's system and employs a time-delay tactic to evade automated sandboxes before initiating the download.
  4. Payload: After a few seconds, a script triggers the download of a rogue, portable installer for ScreenConnect.
  5. Execution: The victim is socially engineered into running the installer and granting the attacker remote access.

This method is effective because it leverages multiple trusted brands (Microsoft, ScreenConnect) and uses techniques designed to bypass both security filters and automated analysis.

Technical Analysis

The abuse of legitimate RMM tools is a form of Living-off-the-Land (LotL) attack. By using software that is often allowlisted and trusted within corporate environments, attackers can evade security products that focus on blocking known malicious files.

A key technical detail, highlighted in a CISA advisory, is the use of portable executables. Unlike full installers, these portable versions do not require administrator privileges to run. They execute within the user's context, which means even standard users on a locked-down machine can be tricked into giving an attacker remote control. This circumvents security policies that are designed to block unauthorized software installations but not necessarily the execution of standalone binaries.

MITRE ATT&CK Techniques

Impact Assessment

The impact of a successful RMM attack can be severe, especially for the targeted financial sector. Once an attacker has remote access to an employee's computer at a financial institution, they can potentially access sensitive customer data, internal banking systems, and execute fraudulent transactions. For commercial banking clients, this could lead to account takeover and significant financial theft. The 475% increase indicates that this is a highly effective and profitable attack method for cybercriminals. The reliance on social engineering makes user awareness and training a critical, yet often fallible, line of defense.

IOCs — Directly from Articles

No specific indicators of compromise were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams should hunt for the following to detect abuse of RMM tools:

Type
Process Name
Value
ScreenConnect.Client.exe, AnyDesk.exe
Description
The execution of RMM client binaries, especially if initiated by a browser or email client.
Type
Command Line Pattern
Value
*.exe --<session_id>
Description
Many RMM tools are launched with a session ID or code as a command-line argument. Monitor for these patterns.
Type
Network Traffic Pattern
Value
Outbound connections to known RMM relay servers
Description
Monitor for connections to domains like screenconnect.com or anydesk.com from user workstations that do not normally use these tools.
Type
Log Source
Value
Web Proxy Logs
Description
Look for downloads of executable files from untrusted sources, especially following a redirect from a trusted service like Power BI.

Detection & Response

Detection:

  1. Application Control: Use application allowlisting to prevent the execution of unauthorized software, including portable RMM tools. If RMM tools are required, restrict their use to specific users and source IPs. (D3FEND: D3-EAL: Executable Allowlisting)
  2. Endpoint Monitoring: Use an EDR solution to monitor for suspicious process chains, such as a web browser or Office application spawning an RMM client process. (D3FEND: D3-PA: Process Analysis)
  3. Network Monitoring: Monitor for outbound connections to known RMM service domains and IPs. Alert on connections from devices or users who are not authorized to use such tools. (D3FEND: D3-NTA: Network Traffic Analysis)

Response:

  1. Terminate Session: If a malicious RMM session is identified, terminate the process on the endpoint immediately.
  2. Isolate Host: Isolate the affected host from the network to prevent further malicious activity.
  3. Investigate: Conduct a forensic analysis to determine what actions the attacker took while they had access.

Mitigation

  • User Training: This is the most critical mitigation. Users must be trained to recognize social engineering tactics and to never grant remote access to unsolicited helpers, regardless of how legitimate the software appears.
  • Restrict RMM Tools: For most organizations, RMM tools should be blocked by default. If a specific tool is needed for legitimate IT support, it should be explicitly allowlisted and its use should be tightly controlled and monitored.
  • Principle of Least Privilege: Ensure users do not have local administrator rights. While portable RMM executables can run without them, lacking admin rights prevents the attacker from making persistent system-level changes.

Timeline of Events

1
September 10, 2026
Huntress first observed the campaign abusing Microsoft Power BI domains.
2
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Train users to recognize social engineering and the risks of granting unsolicited remote access.

Use application allowlisting to block the execution of unauthorized RMM tools, including portable versions.

Use EDR to detect suspicious process chains, such as a browser spawning an RMM client.

Timeline of Events

1
September 10, 2026

Huntress first observed the campaign abusing Microsoft Power BI domains.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

phishingrmmscreenconnectanydesksocial engineeringfortrahuntresspower bi

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.