MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via Help Net Security

Threat Actors Weaponize Legitimate System Management Tools in Nearly Half of Incidents

Image via Help Net Security
Image via Help Net Security

Security researchers found that attackers exploited legitimate remote monitoring and management software in 45 percent of endpoint incidents during the first quarter of 2026, representing a 277 percent year-over-year increase from 2025. Once installed through phishing or deception, RMM tools grant persistent access that blends seamlessly with normal administrative activity, and attackers often layer additional remote access utilities to create multiple backdoors. Organizations should maintain an inventory of approved RMM solutions and establish detection methods for unauthorized tools on their networks.

Expanded Detail

Attackers have discovered that deploying commercially available administrative software provides a nearly invisible entry point into corporate networks. Because legitimate IT departments routinely use these same tools for standard operations, malicious installations blend seamlessly into normal system activity, allowing intruders to maintain long-term access without triggering immediate suspicion. The dramatic increase in this technique reflects how adversaries increasingly favor established software over custom-built malware.

The sophistication of delivery mechanisms has also evolved. Rather than relying solely on traditional phishing, attackers now craft convincing fake service agreements and vendor communications to trick users into installing compromised versions of these tools. Once established, attackers frequently layer multiple remote access utilities on a single device, creating redundant backdoors that ensure persistent access even if one avenue of compromise is discovered and removed.

Context

Organizations across industries may face heightened risk if their security teams cannot reliably distinguish legitimate administrative activity from unauthorized access attempts. Companies relying heavily on remote management infrastructure could experience delayed detection of breaches, potentially extending the window during which attackers extract data or establish ransomware footholds. The findings suggest that endpoint security strategies focused primarily on blocking suspicious software may prove inadequate, requiring instead stronger authentication protocols and behavioral monitoring to identify unusual administrative patterns.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
Attackers Hide Backdoors Inside Counterfeit Email Security Software · Cybersecurity
Third-party software flaw leads to theft of school employee records at Frontline Education · Cybersecurity
Executives Identify AI System Attacks as Their Biggest Security Blind Spot · Artificial intelligence
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “How RMM abuse gives attackers a way in that looks like business as usual.” Browse more stories.