The most common way into a client endpoint right now doesn’t involve malware. It’s the same kind of software your technicians use every day.
Help Net Security, reporting on Huntress research, says attackers used legitimate remote monitoring and management (RMM) software in 45% of the endpoint incidents Huntress recorded in Q1 2026. Huntress calls the category “one hop from ransomware or data theft.” In one case, a fake service agreement installed Tiflux, and the intruder then added UltraVNC, Splashtop, and ScreenConnect to the same device. One phishing click gave the attacker four separate ways back in.
For MSPs, this belongs in the same file as every other “MSP as attack surface” story. Remote access is the core of the service you deliver. When attackers use the same tools, the difference between your session and theirs has to be something you can see, block, and prove.
Why RMM abuse is so hard to spot
The problem isn’t a vulnerability you can patch. As Huntress puts it in the Help Net Security write-up, “the malicious copy and the approved one can behave the same way.” Three patterns keep coming up:
Signed installers dressed up as everyday files. In a July 2026 campaign described by Microsoft and summarized by GBHackers, attackers renamed a legitimate, digitally signed MSP360 installer to look like a Zoom setup file, an e-card, or a PDF reader. Once in, they silently added ScreenConnect as a backup channel. Microsoft found no evidence that a ScreenConnect vulnerability was exploited. The tools were simply misused.
Portable copies that skip installation. CISA’s advisory AA23-025A warns that portable RMM executables run in the user’s context without admin rights, “effectively bypassing common software controls and risk management assumptions.”
Compromised management platforms. When N-able’s N-central was hit by the CVE-2026-18577 authentication bypass this summer, Sophos researchers watched the attacker push AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, and HopToDesk to endpoints, plus a renamed Cloudflare tunnel. Sophos saw a single compromised organization, not a widespread campaign, but the pattern is clear: once inside, attackers stack remote-access tools.
There’s also the clutter attackers hide in. Acronis telemetry from more than 1.8 million managed endpoints found that 63% had more than one remote-access tool installed. When three tools are normal, a fourth doesn’t stand out.
The playbook: inventory, allowlist, prove
Strong MSPs are already moving remote-access governance from tribal knowledge to a documented control. Here’s the sequence.
1. Inventory every remote-access tool
Start with CISA’s first recommendation: audit remote access tools to identify what’s in use and what’s authorized. Pull installed-software reports from your RMM and EDR across every tenant. Look for RMM agents, remote desktop tools, VNC variants, and tunneling utilities such as cloudflared. Record each tool, its version, the client, and who put it there. Anything without an owner is a finding.
2. Approve one tool per job
Pick the approved stack for each purpose: your primary RMM, one remote-control tool, and any vendor-required exceptions. Write it down per client. Vendor tools, such as a line-of-business vendor’s support client, get a named owner and an end date, not permanent standing.
3. Allowlist the approved tools and block the rest
Use application control to allowlist approved RMM programs, and make sure the policy blocks portable executables as well as installations. CISA also recommends blocking inbound and outbound connections on common RMM ports and protocols at the perimeter, and limiting authorized tools to approved access paths such as VPN or VDI. Requiring admin approval for installs matters too: in the MSP360 campaign, a denied UAC prompt stopped the installation.
4. Harden your own console
Your RMM is a privileged identity system for every client you serve. Use named accounts only, phishing-resistant MFA, role-based permissions, and IP or conditional-access restrictions on the console. Patch the platform as urgently as you would a firewall. The N-central incident is a reminder that the management server itself is a target.
5. Alert on anything new
Huntress suggests a simple test: ask which RMM tools are approved and what tips the team off when an unapproved one appears. Your answer should be an alert, not a quarterly review. Flag new remote-access services, RMM processes running from user folders, PowerShell pulling MSI packages, and new firewall rules created for remote agents.
6. Keep proof of who has access
This is where governance becomes evidence. For each client, keep:
The approved remote-access tool list, with owner and business purpose
The current application-control policy and change history
Named technician accounts on the RMM, with MFA status and role
Quarterly access reviews showing who was added, removed, or changed
Alerts raised for unapproved tools, and how each one was resolved
Turn it into a client conversation
Clients don’t need a lecture on RMM abuse. They need three sentences: attackers are using legitimate remote-access software to get in, we’ve documented exactly which tools are allowed on your systems, and anything else gets blocked and investigated. That’s a security program outcome they can understand, and it shows the ownership line between you and them.
It also helps with vendor reviews, insurance applications, and audits, where “who can access our systems remotely?” is a standard question. With Blacksmith InfoSec, the approved tool list, access reviews, and resolved alerts can live alongside the client’s policies and evidence, mapped to the controls they support, so the answer is ready before anyone asks.
Frequently asked questions
Q: What is RMM abuse?
A: RMM abuse is when attackers use legitimate remote monitoring and management software to gain persistent remote access to a device. Because the tools are signed, widely used, and built to run commands and move files, malicious sessions can look like normal IT work. Huntress found RMM abuse in 45% of endpoint incidents in Q1 2026.
Q: How do attackers install RMM tools without exploiting a vulnerability?
A: Most often through phishing. Victims run a file that looks like a meeting invite, document, or software update, but is actually a renamed, legitimate RMM installer. In a July 2026 campaign, Microsoft observed a signed MSP360 installer used this way, followed by a silent ScreenConnect install (GBHackers).
Q: Can application allowlisting stop RMM abuse?
A: It’s one of the most effective controls when it covers both installed and portable versions of unauthorized tools. CISA recommends allowlisting approved RMM programs, blocking common RMM ports at the perimeter, and limiting authorized tools to approved access paths (CISA AA23-025A).
Q: Why should MSPs inventory remote-access tools across every client?
A: Unmanaged tools give attackers places to hide. Acronis telemetry found more than one remote-access tool on 63% of the managed endpoints it analyzed. An inventory with owners for each tool is what makes an unapproved tool stand out.
Q: What evidence shows that remote access is controlled?
A: Useful evidence includes an approved tool list with owners, the application-control policy and its change history, named RMM accounts with MFA status, periodic access reviews, and records of alerts for unapproved tools and how they were resolved.