RMM Abuse Turns Trusted IT Tools Into Attack Paths
Trusted Tools, Unwanted Access
RMM abuse turns everyday IT utilities into a foothold for attackers. Remote monitoring and management tools help administrators support distributed systems. Those same capabilities can also give criminals remote access without building their own infrastructure.
Huntress Cybersecurity Advisor Bryson Byrd joins Mike Vizard to examine this persistent threat. The discussion separates two attack paths: compromising an approved tool and installing an unauthorized one. That distinction matters when teams decide what to monitor and block.
Visibility Before Another Security Purchase
Byrd explains why banning every remote management tool is impractical. Organizations depend on these tools to support employees and maintain systems. Instead, security teams need to identify which products belong in their environments.
Allowlisting approved tools and blocking unexpected alternatives can reduce exposure. Byrd discusses Huntress RMM Guard as one approach to that challenge. He also emphasizes layered defenses rather than relying on a single setting or product.
Effective protection requires cooperation between IT and security. Both teams need shared expectations about authorized software, deployment practices and response responsibilities. Treating security as someone else’s job leaves gaps that attackers can exploit.
AI Raises the Stakes for Security Fundamentals
AI can accelerate attacks and shorten the time available for defenders to respond. However, Byrd argues that longstanding technical debt remains a major concern. Exposed remote access services and outdated software still create opportunities for intruders.
Automation can help contain suspicious activity quickly. Human analysts then bring context and judgment to the investigation. The conversation highlights why speed and expertise should work together rather than compete.
Smaller organizations also face budget and staffing constraints. Byrd calls attention to nonprofits and critical infrastructure operators that cannot simply buy their way out of risk. Practical controls and sustained vendor support matter for these teams.
The discussion closes with a focus on visibility, blocking and defense in depth. Reducing RMM abuse starts with knowing what is running and responding when that changes. Better fundamentals can deliver more value than chasing the latest security trend.
Transcript
Hey guys, thanks for the throw. We're here with Bryson Bird, who's a security advisor for Huntress, and we're having a chat about, well, something that's been a problem for as long as I can remember as it relates to cybersecurity, but it doesn't seem like it's getting a whole lot better anytime soon. It's called remote management and monitoring.
These RMM tools are the favorite attack path and still seem to be the case for as long as anybody can remember. Bryson, A, welcome to the show. Hey, thanks for having me.
I'm really excited to be here and talk about everyone's favorite topic, right? RMM abuse, as well as some of the other things that we're seeing over at Huntress. And B, so this has been going on for as long as I can remember, and we seem to be unable to thwart these attacks.
So what's going on here, and how are they changing? Yeah, I used to do incident response back in the heyday of craziness, also known as the pandemic, right? And we saw some of this back then with certain vendors that were abused more than others, but we're seeing a huge spike, right?
So Huntress itself, we've seen year over year a 277% increase. Let me repeat that, a 277% increase, right? So even though we've been seeing this as an industry for a little while now, it's ramped up to a whole different level these days.
And I think there's a contributing amount of factors. One is there's more open source RMMs out there than potentially ever, right? So they're pretty easy to spin up.
And two is just like the game of Whac-A-Mole will continue, right? So the second that we kind of catch on to some trade craft maybe that they're using with a vendor, shout out to vendors such as Anydesk that have recognized these as issues, and starting to clamp down on those. They kind of pivot over to another vendor or to multiple other vendors, right?
So we're seeing that overall, this increase is led by the fact that why, if you're an attacker, are you going to spin up all your infrastructure that takes so much time and resources when you can just use tools that have been vetted, right? So, we're seeing it at a huge scale right now. So what is the challenge with fixing all of these RMM tools?
" I just find it kind of baffling that we keep having this issue over and over again. I think for those of us that have been around for a little bit, we're all a little baffled by some of the elementary attacks, right? Because at the end of the day, the kind of attack we're talking about is a living off the land attack, right?
That's effectively what we're talking about, which is an old school term of using known IT resources to leverage these attacks. The key here, and I think what makes it so difficult is, again, the complexities of how many vendors we're talking about, and not all of these are for-profit vendors. Some of them are open source, some of them are just projects that people have kicked off that work to solve a solution in IT.
So the defense is also not always the easiest one toggle switch and we're good. It's a defense in depth that relies on visibility, right? We've got to have a layered approach into not only being able to prevent these types of things, but also just at a bare bones, we've got to be able to see them.
So there are players that are starting to kind of take notice of that. We at Huntress are one of them, right? Through trying to figure out, how do we get into these environments and really manage the security posture of those environments to help thwart some of these attacks?
And are people going to the trouble of creating malware? Why bother if I can just get your credentials and log into your RMM system and just sit there, and for, I don't know, I can make it look like I'm a regular citizen on your network for weeks before I go do something malicious, right? Yeah, if they can leverage an existing RMM, that's game, set, match, right?
But oftentimes, we're seeing them actually spin up their own RMM, right? So it's not always one that's existing in the environment. A good example is maybe an IT company, a managed service provider, otherwise leverages something like Anydesk.
They may spin up TeamViewer through a malicious download off of either an advertisement, a mail campaign for phishing, whatever the case may be. So the key callout there is it's not just the ones that are deployed that are the issues. It's potentially new ones being deployed that your IT team doesn't know about or did not authorize.
So will AI agents complicate that? Because I can envision a world where there's a malicious AI agent installing an unknown RMM and then going to town, and this could all happen at machine speed. So before I even knew what happened, the whole company could be infected with something.
It's an interesting world we live in with AI, that's for sure, right? I'm glad you bring up machine speed because this is another key thing that we are seeing right now. Our Huntress SOC is really investigating and seeing over and over is the compression window of the speed at which these attacks, whether we're talking about RMM or some more traditional ransomware attacks, right?
Maybe they get in through an RMM install and then they detonate through ransomware using that RMM, or maybe it's some other path. But regardless, we are seeing that mean time of, that dwell time rapidly decrease over time, right? These folks, unfortunately, with AI, they are moving at machine speed with these tools just like us as defenders are.
So part of the challenge is meeting them at that speed. So we need the visibility, we need the defense in depth, and then on the back end of it, when we see something, we've got to move quickly because they are, too. Is it your sense that maybe organizations are being a little more proactive about this, or is this one of those, unfortunately, all too common scenarios where nobody does something about it until after they've been victimized?
Yeah, I think this is one of those situations where part of the responsibility is on us as vendors to continue to sound these alarms, right? This isn't about, "Let me come over here. " It's truly about getting the word out that this is a problem, and this is something that needs to have those proactive resources leveraged towards it.
Because you bring up a good point around a lot of times we as humans, we're just not good at proactive. I worked in prevention for a long time, in my teenage years. Yeah, wasn't your average teenager.
But I learned that lesson the hard way even before I took a psychology class, right? Is that we as humans, prevention is hard for us. With that being said, there's a lot of great work going on across MSPs, across individual IT teams, and others to heed this alarm and take it seriously to stop some of this stuff in its track.
Whether that be through vendor partnerships like us at Huntress, whether that be through other partnerships, through some of the other SOC vendors. At the end of the day, we're all in the same fight to try to stop some of this. Do we need our security and IT teams maybe to work more closely together to resolve these issues?
Because I think a lot of the RMM stuff is deployed typically by IT people for some function or another, and the security people aren't necessarily going looking for that specifically, or should they? Or is there a conversation to be had here? Yeah, I think one of the uncomfortable truths that maybe not everybody will agree with me personally on, and that's fine if they don't, but I don't believe that there's much of a separation these days between software development and security, IT and security, security and IT, security and software development.
I think all of these worlds are merging at a rate that we never kind of envisioned, and I think that AI is condensing that merger as well, right? Because it's forcing teams to understand that cross-function more and more and to communicate across functions more and more. " Because it's the only path forward is to make sure that security understands that visibility of what should be in the environment and what shouldn't.
And IT is also helping be a second set of eyes on the environment as well and being proactive on some of the initiatives to make sure it's secure when it's deployed. So what's keeping you up at night about all this? " I think for me, it's the prevention side.
Me personally, right? We talked about a little bit on the prevention versus reactive. AI itself is not keeping me up at night, right?
But what is keeping me up at night is all of the debt that across the board, whether we're talking about critical infrastructure, whether we're talking about a school, whether we're talking about my sister's medical practice that she has, whatever the case may be, there's a lot of technical debt that's been accumulated for a very long time. And what AI is doing is, is it's going in and it's leveraging that technical debt. An example being, hey, maybe there's a port open, such as our good old friend RDP, that was open in one of these environments.
Years past, that was a problem that maybe you had a couple of months to recognize, see, and fix. AI is shrinking that gap at a rate that's alarming to where that may be days or hours that you have to see that and fix it. So these debts that we've accumulated over years of not paying attention to certain things, AI's making it to where we truly need security and depth, and we need to make sure that we're paying attention to the entire sack, not just the perimeter or not just the identity or not just the endpoint.
It's truly a cohesive environment that's needed at this point. To your point about that, it is not uncommon for organizations to kind of, quote-unquote, "sweat their IT assets," and they run things long past their shelf life because everybody's trying to squeeze as much out of a dollar as they can. But does that wind up being self-defeating?
Because ultimately, the older that stuff is, the more technical debt there is in it, more vulnerabilities there might be in it, and that is what's going to get exploited. So do I need to make a conscious decision to always be as current as possible? Yeah, it's an interesting paradigm, right?
And it's really easy as a security practitioner for me to sit in an ivory tower and lay the blame at the feet of people with very strapped budgets, right? Whether it be non-profits, whether it be critical infrastructure, whatever the case may be. I think that it's really easy to blame it on that.
I think that there is a certain level of the days of allowing hardware to age 10 years are probably behind us overall. " And I'm not talking about Huntress, I'm talking about the Microsofts of the world, I'm talking about the Apples of the world, and others that are supplying these pieces of software, even just at a bare bones for endpoints. We need those partnerships to ensure that software patches are being leveraged longer than what they have in the past as well, right?
So I think that all of this is part of the solution. " I think that some of the vendors that are creating some of the servers and other things should be held at a higher standard to make sure that this stuff is patched long-term, not just in an interim of three hours or something like that. I mean, sorry, three years or something like that.
Mm-hmm. So we talked a little bit about this is all happening at machine speed now. Is this happening faster than we mere mortals can keep up with?
So how do we kind of wrap our heads around a world where maybe it's Whac-A-Mole, but it's Whac-A-Mole between AI adversaries, and we're trying to supervise this? How does that kind of play out in your mind? Yeah, at the end of the day, it's not just the bad guys that have machine speed on their side, right?
Like we at Huntress, some of the other SOCs, some of the other teams that are fighting these adversaries, we've got these tools at our disposal as well, and I think that the real secret sauce to stopping this is not actually the machine speed. The machine speed buys us time for the investigation, but it's the humans to truly dig in and understand what's happening once it's kind of been stopped, right? So using our good clinker overlords, AI agents, to be able to stop some of this in its tracks, and then our humans to come in and really marry that level of information and experience that they have with that machine speed to be able to stop these attacks.
I think that that's where I have the most optimism is I get a front row seat to this on our side of the house to see how some of this is working in real-time, and that's what gives me a lot of optimism for it. Is there another way to think about this that doesn't require us to use RMM tools in the first place? And there's other ways of going after this whole thing because, well, if that particular well is, for whatever reason, poisoned a lot, maybe we should be drinking water somewhere else.
Yeah, I think it's important again to reemphasize there's two different types of attacks on RMMs, right? There's breaching an existing RMM that is leveraging an attack that's already in the environment, and then there's leveraging an RMM to install it into the environment that maybe it didn't otherwise exist previously, right? On the front of the first one on breaching an existing one, an existing tool, we've seen some of the devastating effects of that taking place, but that's way less prevalent than the second, right?
When we start talking about the second one of introducing some of these RMMs, I think it's easier to stop some of this if you have visibility and you have some of the defense in-depth strategies that we talked about previously. " Because at the end of the day, the uncomfortable truth is that so many IT teams are going to continue to have to rely on these. Because getting hands on keyboard or going to some of the old architecture of everything on the same network in order to control it, that's just not the world that we live in anymore, unfortunately.
There's some environments that'll work in, but disproportionately, we need these types of tools to be able to work in robust and very different networks that maybe we don't control. " Right? The key is to allow list the one that you expect and deny the ones you don't, right?
That's kind of the key, and that's where we're headed at Huntress with some of our offerings with endpoint security posture management is, and RMM guard is being able to see that visibility and you as an owner of that infrastructure, stop it in its tracks. But all told, blocking all RMMs in every network, it's just not reasonable. You think that the adversaries are kind of laughing at us because we have a lot of focus on all kinds of interesting attack vectors and possibilities that could happen.
" Yeah, so again, my history in this crazy cybersecurity world, I've talked to some of these threat actors, and there's a lot of things I think they laugh at us for, but there's a lot of things we laugh at them for, too, right? If you haven't seen some of the recent news around some of the ransomware gangs beefing, right? I've had some good popcorn moments myself.
Look, it's a game of cat and mouse. I think both sides have some jabs to throw at the other one. But at the end of the day, bringing it back, it's really the basics that are stopping these attacks, right?
It's visibility, it's blocking, and it's defense in depth that is really getting in the way of these attackers more than it is like the shiny new AI tool that everybody wants to sell. All right, folks, you heard it here. No matter how amazing things might get, don't forget the fundamentals because the bad guys aren't going to go to any more trouble than they possibly have to.
And that means if it's easy just to use an RMM tool, they'll do that long before they figure out how to hijack your AI agent. Hey, Bryson, thanks for being on the show. Thanks for having me, Mike.
All right, and back to you guys in the studio.