More RMM Tools In the Wild, (Tue, Oct 6th)

Summary

The article reports on the increasing trend of threat actors abusing Remote Management and Monitoring (RMM) tools. Following a previous mention of ScreenConnect, the author has identified another RMM tool being exploited in the wild by malicious actors.

IFF Assessment

FOE

The use of RMM tools by threat actors indicates a growing attack vector and a challenge for defenders in distinguishing legitimate administrative traffic from malicious activity.

Defender Context

Defenders should be aware of RMM tools being misused by threat actors as an attack vector. It's crucial to monitor network traffic for unusual RMM activity and ensure proper access controls and logging are in place for these administrative tools.

Read Full Story →