Threat actors continue to exploit Remote Monitoring and Management (RMM) tools to compromise MSPs and their downstream customers at scale. A June 2025 incident analyzed by Huntress shows a threat actor who compromised an MSP's Atera RMM instance, then used it to target three customer organizations — adding rogue local admin accounts and installing Cloudflared tunnels for persistent access. The attack mirrors the 2021 Kaseya VSA supply chain attack in approach. RMM abuse accounted for 17.3% of all remote access methods in Huntress' 2025 Cyber Threat Report. Defensive recommendations include auditing authorized RMM tools, enforcing VPN-only access, implementing application controls, reviewing execution logs, deploying EDR, and keeping RMM software patched.

7m read timeFrom huntress.com
Post cover image
Table of contents
One RMM compromise, three businesses hitRMMs and MSPs: Dual targets ripe for threat actorsA complete guide to preventing RMM abuse