A rise in attacks exploiting RMM tools like ScreenConnect enables system control via phishing tactics.
Cybersecurity researchers have observed a rise in cyber-attacks exploiting remote monitoring and management (RMM) tools for initial access via phishing.
According to the new findings from the DarkAtlas research project, advanced persistent threat (APT) groups are abusing popular RMM platforms, including AnyDesk, ConnectWise ScreenConnect and Atera, to gain unauthorized control of systems.
While AnyDesk has become easier to detect, leading many attackers to move away from it, ScreenConnect has recently gained traction among adversaries.
Developed by ConnectWise, ScreenConnect is designed to let IT administrators deploy tasks, manage devices and provide remote support across multiple operating systems, including Windows, macOS, Linux, iOS and Android.
Author summary: Hackers exploit RMM tools for network intrusions.