Threat actors continue to exploit Remote Monitoring and Management (RMM) tools to compromise MSPs and their downstream customers at scale. A June 2025 incident analyzed by Huntress shows a threat actor who compromised an MSP's Atera RMM instance, then used it to target three customer organizations — adding rogue local admin accounts and installing Cloudflared tunnels for persistent access. The attack mirrors the 2021 Kaseya VSA supply chain attack in approach. RMM abuse accounted for 17.3% of all remote access methods in Huntress' 2025 Cyber Threat Report. Defensive recommendations include auditing authorized RMM tools, enforcing VPN-only access, implementing application controls, reviewing execution logs, deploying EDR, and keeping RMM software patched.