Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
Huntress details phishing campaigns installing rogue ITarian and ScreenConnect RMM clients with SYSTEM persistence, amid a 277% spike in RMM abuse.
Huntress SOC investigated three incidents where phishing lures (a TransferXL secure-document email and fake ScreenConnect document shares) tricked employees into installing rogue RMM clients. Attackers stacked ITarian plus ScreenConnect for redundant SYSTEM-level persistence, ran defense-evasion binaries such as HideUL_x64.exe, and in one case used a client hidden for five months to set malicious inbox rules. Huntress tracked a 277% spike in RMM abuse in 2025 and now sees it in roughly 40% of incidents it investigates.
60