What are Remote Monitoring and Management (RMM) Tools?
Written by: Lizzie Danielson
Published: 9/25/2026
Key Takeaways
- RMM abuse increased 277% year over year in 2025 and appeared in nearly a quarter of incidents investigated by Huntress.
- Attackers favor RMM tools because they’re legitimate, signed, widely trusted, and designed to provide persistent interactive access.
- RMM abuse can begin with phishing, social engineering, stolen credentials, exploitation of an RMM vulnerability, or compromise of an MSP’s RMM instance.
- Attackers may install multiple RMM tools to create redundant access paths and complicate detection and containment.
- The most effective starting point is to inventory approved RMM software, restrict unauthorized applications, and monitor a tool’s behavior, not simply its presence.
What are remote monitoring and management (RMM) tools?
Remote monitoring and management (RMM) tools are legitimate software that IT teams and managed service providers (MSPs) use to remotely monitor, maintain, troubleshoot, and control devices. RMM abuse happens when threat actors misuse those same tools to gain remote access, maintain persistence, run commands, steal data, or deploy ransomware.
Here's the part that trips people up: an RMM tool isn't inherently malicious. The software itself is the same whether an IT admin is patching a laptop or an attacker is quietly working through your network. The risk comes from unauthorized installation, compromised credentials, vulnerable deployments, or suspicious behavior.
What is an RMM tool?
RMM software gives IT teams and MSPs a single place to manage devices at scale. That typically covers:
- Applying patches and updates
- Monitoring endpoint health
- Troubleshooting devices remotely
- Automating routine maintenance tasks
- Supporting distributed or remote workforces
- Managing multiple customer environments from one console
The whole value proposition—one login, broad reach, minimal friction—is exactly the problem from a security standpoint. The same administrative capabilities that let your IT team push a patch to 200 devices in one click can give a threat actor command execution, file access, persistence, and a path to move laterally through your environment, all through a tool your security stack already trusts.
Why do attackers use RMM tools?
They blend in with normal administration
Legitimate RMM binaries and traffic often don't trigger the same alerts as custom malware would. A threat actor running commands through ScreenConnect or AnyDesk can look, on paper, like an admin doing routine maintenance because to most detection tools, that's exactly what it looks like.
They provide persistence
RMM tools are built for continuous remote access; that's their main job. Once a tool is compromised or maliciously installed, that same built-in persistence becomes a durable foothold for the attacker, no extra malware required.
They're easy to obtain
Building custom remote-access malware takes time and skill. Downloading a commercial RMM tool takes minutes. Huntress has observed abuse involving tools including ScreenConnect, Atera, AnyDesk, RustDesk, Splashtop, SimpleHelp, TeamViewer, Tiflux, and others—all off-the-shelf, all legitimate software.
They can help attackers reach many businesses at once
RMM tools are often the backbone of how MSPs manage their customers, which makes them a high-value target. When an MSP's RMM instance is compromised, threat actors can potentially gain access to every downstream customer connected to it, turning one compromise into many.
RMM abuse by the numbers
Finding | Source |
RMM abuse increased 277% year over year in 2025 | |
RMM abuse accounted for nearly 24% of observed incidents | |
More than 50% of cases following suspicious Atera activity were linked to ransomware | Huntress, "RMM Abuse: When IT Convenience Bites Back" |
A 2021 Kaseya attack affected an estimated 50 to 60 MSPs and 1,500 to 2,000 downstream organizations | Huntress, "RMMs: A Gateway for Bulk Attacks on MSP Customers" |
How RMM abuse happens
Most RMM abuse follows a recognizable path:
- Initial access: Phishing, social engineering, stolen credentials, exposed remote access, or exploitation of an RMM vulnerability gets the attacker in the door.
- RMM installation or takeover: The attacker installs a rogue tool, hijacks an already-approved one, or compromises an MSP's RMM account directly.
- Persistence: The attacker creates a service, installs another RMM tool as backup, or sets up a tunnel to keep access alive.
- Discovery and credential theft: The attacker profiles the system, pulls browser data, runs commands, or starts moving laterally.
- Impact: Ransomware deployment, data theft, extortion, fraud, or simply continued quiet access.
Huntress investigations have traced this exact sequence across phishing-delivered RMM installers, stolen RMM credentials, multiple simultaneous remote-access tools, credential theft, and ransomware deployment.
How to detect RMM abuse
Detection has to focus on behavior, not just which product is installed. Watch for:
- An RMM executable running from a user-writable or temporary directory
- An unexpected RMM installer delivered by email or downloaded from a website
- New RMM services appearing outside approved change windows
- RMM activity from an unusual user, endpoint, location, or time of day
- Command-line activity launched through an RMM process
- An approved RMM connecting to an unfamiliar server or domain
- Multiple RMM tools installed on the same endpoint
- RMM activity followed by account creation, security-tool disablement, tunneling, credential theft, or ransomware behavior
- RMM activity spanning multiple customer environments from a single MSP account
An approved RMM tool can still be abused. That's why you need a real baseline, for users, devices, time of day, destinations, executable paths, and expected administrative actions rather than a simple allowlist of tool names.
How to prevent RMM abuse
- Maintain an inventory of every installed remote-access and RMM tool across your environment.
- Define exactly which tools are approved for each environment and treat anything else as unauthorized.
- Use application controls to block RMM software that isn't on your approved list.
- Require multi-factor authentication (MFA) for every RMM and remote-access account.
- Restrict RMM administration to approved networks or VPN connections.
- Review RMM logs and endpoint telemetry regularly, not just after something looks wrong.
- Remove legacy RMM tools whenever you change MSPs or service providers.
- Keep approved RMM software patched and current.
- Prepare employees with security awareness training to recognize fake invoices, document shares, invitations, and service agreement.
FAQs
No. RMM tools are legitimate and widely used for good reason—they're how IT teams and MSPs manage devices efficiently at scale. The risk isn't the software; it's unauthorized installations, compromised credentials, and unmonitored behavior.
Malware is built to be malicious. RMM abuse uses signed, legitimate software that your security tools already trust, which is exactly why it's harder to catch with traditional detection methods.
An MSP's RMM instance often connects to many downstream customer environments at once. Compromising a single MSP account can give a threat actor a path into every business that MSP manages.
An allowlist helps, but it's not enough on its own. Approved tools can still be abused through stolen credentials or misconfiguration, so you need behavior-based monitoring alongside your inventory and access controls.
Additional Resources
- Read more about What is a Disinformation Campaign in Cybersecurity & Why Are They Harmful?Understand disinformation campaigns and their cybersecurity impact, tactics, and defense strategies. Learn to spot, prevent, and respond.
- Read more about What is Over-the-Air Technology? | Cybersecurity GuideWhat is Over-the-Air Technology? | Cybersecurity GuideLearn how over-the-air (OTA) technology works, common security vulnerabilities, and best practices for protecting wireless update systems.
- Read more about What is Domain Spoofing? | Cybersecurity 101What is Domain Spoofing? | Cybersecurity 101Learn how domain spoofing works, its impact on cybersecurity, and practical ways to prevent spoofing attacks. Protect your organization from phishing and fraud.
- Read more about What is a User Agent?What is a User Agent?Discover what a user agent is and how it facilitates web interactions. Learn about User-Agent strings and their role in web optimization.
- Read more about What is cybersecurity? 5 Tips to Staying SecureWhat is cybersecurity? 5 Tips to Staying SecureLearn what cybersecurity is, why it’s essential, and 5 tips for improving cybersecurity to protect yourself online. Stay informed and secure.
- Read more about What a Skimmer? Stay Protected from Credit Card ScammersWhat a Skimmer? Stay Protected from Credit Card ScammersLearn essential tips to detect and avoid credit card skimmers. Stay vigilant with these security measures to safeguard your financial data.
- Read more about What Is User Identity Management? | Huntress Cybersecurity 101What Is User Identity Management? | Huntress Cybersecurity 101Learn what user identity management is, how it protects your organization, and why identity and access management (IAM) is essential to modern cybersecurity.
- Read more about What is Machine Learning? ML in Cybersecurity ExplainedWhat is Machine Learning? ML in Cybersecurity ExplainedDemystifying machine learning (ML) for cybersecurity. Learn how ML algorithms detect threats, improve security, and protect your organization
- Read more about SOC Analyst Career Guide: Your Path to Cybersecurity SuccessSOC Analyst Career Guide: Your Path to Cybersecurity SuccessLearn the exciting role of SOC analysts in cybersecurity, their crucial responsibilities, and actionable tips to launch your career in threat hunting.