Huntress SOC has documented a significant uptick in attacks exploiting CVE-2026-1731, a critical unauthenticated RCE vulnerability in Bomgar (BeyondTrust Remote Support). Since early April 2026, multiple incidents have been observed including LockBit 3.0 ransomware deployments, MSP compromises affecting 78 downstream businesses, and a dental software company breach impacting three downstream organizations. Threat actors are using compromised Bomgar instances to conduct domain reconnaissance, add persistent admin accounts, deploy additional RMMs (AnyDesk, Atera, ScreenConnect), and kill EDR tools using BYOVD techniques (PoisonX.sys/PoisonKiller). Patched versions are available since February (Remote Support 25.3.2+, Privileged Remote Access 25.1+). Organizations are urged to patch immediately, audit RMM usage, and monitor for unauthorized admin account additions.

8m read timeFrom huntress.com
Post cover image
Table of contents
Key takeawaysThe tradecraftOngoing incidentsIndicators of Compromise