---
title: "Rogue RMMs: Common Social Engineering Tactics We Saw in 2025"
url: https://daily.dev/posts/rogue-rmms-common-social-engineering-tactics-we-saw-in-2025-p3glcwee6
source_url: https://www.huntress.com/blog/rogue-screenconnect-social-engineering-tactics-2025
type: article
source: "Huntress Blog"
published: 2026-05-31T07:44:04.029Z
updated: 2026-05-31T09:02:20.613Z
tags: ["security", "phishing"]
reading_time: 9
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rogue RMMs: Common Social Engineering Tactics We Saw in 2025

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 9 min read · 0 upvotes · 0 comments

## Summary

Huntress SOC analysts detail recurring social engineering tactics used by threat actors in 2025 to deploy rogue ScreenConnect RMM installations. Common lures include fake Social Security statements, event invitations, and overdue invoices disguised as executables. The post provides concrete IoCs including top malicious domains, SHA256 hashes, and executable naming patterns observed across multiple victim organizations. ScreenConnect accounts for 74.5% of abused remote access tools seen by Huntress. Mitigation recommendations include security awareness training, RMM auditing, log review, and Managed EDR solutions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/rogue-screenconnect-social-engineering-tactics-2025>

## Similar posts on daily.dev

- [RMM Abuse Explodes as Hackers Ditch Malware](https://daily.dev/posts/rmm-abuse-explodes-as-hackers-ditch-malware-v44l6tyt4) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/rogue-rmms-common-social-engineering-tactics-we-saw-in-2025-p3glcwee6)
