Huntress SOC analysts have documented a growing attack pattern where threat actors chain multiple remote monitoring and management (RMM) tools to maintain persistent access in victim environments. Attackers use phishing lures (fake contracts, holiday invitations, social security documents, bid transcripts) to trick users into installing a first RMM like GoTo Resolve, PDQ, or ITarian, then leverage that foothold to deploy secondary tools such as ScreenConnect or SimpleHelp. In some cases, three RMMs are chained together. The post includes real incident examples from October–November 2025, explains why legitimate RMM tools are hard to detect as malicious, and provides defensive recommendations including asset inventory, application controls, RMM auditing via LOLRMM, and log monitoring. A full list of indicators of compromise (IOCs) with attacker-controlled domains is included.