More RMM Tools In the Wild, (Tue, Oct 6th)
Summary
The article reports on the increasing trend of threat actors abusing Remote Management and Monitoring (RMM) tools. Following a previous mention of ScreenConnect, the author has identified another RMM tool being exploited in the wild by malicious actors.
IFF Assessment
FOE
The use of RMM tools by threat actors indicates a growing attack vector and a challenge for defenders in distinguishing legitimate administrative traffic from malicious activity.
Defender Context
Defenders should be aware of RMM tools being misused by threat actors as an attack vector. It's crucial to monitor network traffic for unusual RMM activity and ensure proper access controls and logging are in place for these administrative tools.