Security researchers are reporting a dramatic surge in phishing attacks that abuse legitimate Remote Monitoring and Management (RMM) software. A report from Fortra indicates a 475% increase in such attacks in the first nine months of 2026 compared to the entirety of 2025. These campaigns primarily target North American financial institutions and rely on social engineering to trick victims into granting attackers remote access to their systems using trusted tools like ScreenConnect and AnyDesk. This 'living off the land' technique bypasses traditional malware detection by using legitimate software for malicious purposes. The use of portable executables allows these tools to run without administrative privileges, further complicating detection and prevention efforts.
The core of this threat is social engineering. Attackers contact victims, often posing as technical support or a trusted entity, and convince them to install and authorize a legitimate RMM tool. Once granted access, the attacker has full control over the victim's machine, enabling them to steal data, install further malware, or conduct financial fraud.
A specific campaign analyzed by security firm Huntress demonstrates the evolving sophistication of these attacks. First seen on September 10, 2026, this campaign abused Microsoft Power BI domains to add a layer of legitimacy to the initial lure.
powerbi.com domain.This method is effective because it leverages multiple trusted brands (Microsoft, ScreenConnect) and uses techniques designed to bypass both security filters and automated analysis.
The abuse of legitimate RMM tools is a form of Living-off-the-Land (LotL) attack. By using software that is often allowlisted and trusted within corporate environments, attackers can evade security products that focus on blocking known malicious files.
A key technical detail, highlighted in a CISA advisory, is the use of portable executables. Unlike full installers, these portable versions do not require administrator privileges to run. They execute within the user's context, which means even standard users on a locked-down machine can be tricked into giving an attacker remote control. This circumvents security policies that are designed to block unauthorized software installations but not necessarily the execution of standalone binaries.
T1219 - Remote Access Software: The central technique is the abuse of legitimate RMM tools like ScreenConnect for malicious remote control.T1566.002 - Spearphishing Link: The initial vector is a link in a phishing email.T1059.007 - JavaScript/TypeScript: The attacker's website uses a script to programmatically trigger the download after a delay.T1598.002 - Spearphishing Link: The use of trusted services like Power BI to host the initial link is a form of 'spearphishing via service' to enhance legitimacy and evade filters.The impact of a successful RMM attack can be severe, especially for the targeted financial sector. Once an attacker has remote access to an employee's computer at a financial institution, they can potentially access sensitive customer data, internal banking systems, and execute fraudulent transactions. For commercial banking clients, this could lead to account takeover and significant financial theft. The 475% increase indicates that this is a highly effective and profitable attack method for cybercriminals. The reliance on social engineering makes user awareness and training a critical, yet often fallible, line of defense.
No specific indicators of compromise were provided in the source articles.
Security teams should hunt for the following to detect abuse of RMM tools:
ScreenConnect.Client.exe, AnyDesk.exe*.exe --<session_id>screenconnect.com or anydesk.com from user workstations that do not normally use these tools.Web Proxy LogsDetection:
D3-EAL: Executable Allowlisting)D3-PA: Process Analysis)D3-NTA: Network Traffic Analysis)Response:
Train users to recognize social engineering and the risks of granting unsolicited remote access.
Use application allowlisting to block the execution of unauthorized RMM tools, including portable versions.
Use EDR to detect suspicious process chains, such as a browser spawning an RMM client.
Huntress first observed the campaign abusing Microsoft Power BI domains.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.