CYBERSECURITY MANAGED SERVICE PROVIDERS

Hardening RMM Across Every Client You Manage: Why MSPs Can No Longer Ignore Their Own Attack Surface

TM
Techmediaglobal
| 4 min read
277%
RMM ABUSE JUMP IN 2025
24%
OF INCIDENTS OBSERVED
53%
DROP IN TRADITIONAL TOOLS
78
BUSINESSES HIT IN ONE ATTACK

Remote monitoring and management (RMM) platforms sit at the core of every managed service provider's operations — and that's precisely why attackers have turned them into a favorite weapon. Rather than building custom malware, threat actors are increasingly hijacking legitimate RMM agents already trusted inside client environments, using them as a single control point for command-and-control, lateral movement, and ransomware deployment.

A Sharp Shift in Attacker Tactics

The use of traditional hacking tools plummeted by 53% as cybercriminals instead built entire playbooks around RMM tools to drop malware, steal credentials, and execute commands. The Huntress 2026 Cyber Threat Report recorded a 277% jump in RMM abuse during 2025, with RMM abuse now accounting for 24% of all incidents the company observed.

Other vendors reported similar patterns. 30% of the security incidents Blackpoint Cyber responded to involved RMM software abuse, with CAPTCHA and ClickFix scams driving 58% of malicious activity detected. Separately, RMM tool abuse was found to be the single biggest endpoint threat in one analysis, accounting for 26% of all detections, with tools such as ScreenConnect, AteraAgent, and MeshAgent used to gain unauthorized access.

Why MSPs Face an Amplified Risk

The risk to MSPs is amplified by their very structure: one compromised RMM instance can mean access to dozens of downstream clients simultaneously. When attackers compromise an RMM solution managed by an MSP, they can immediately access multiple downstream customers in a massive supply chain attack.

A recent real-world example bore this out when an attack on an MSP led to the mass isolation of 78 businesses and subsequent exploitation across four downstream customers.

"Stealing credentials and abusing tools already trusted in the environment is easier than finding a zero-day exploit in an appliance."

— Threat Intelligence Engineer

What Endpoint Hardening Looks Like in Practice

Hardening starts with the basics most MSPs already know but inconsistently enforce: mandatory multi-factor authentication (MFA) on every RMM admin account, IP allow-listing for console access, and removal of stale or unused agents from client endpoints. From there, the priority shifts to patching — RMM platforms with known vulnerabilities are routinely scanned and exploited within days of disclosure.

Role-based access control matters too — not every technician needs domain-admin-level reach across every client, and limiting blast radius is now a baseline expectation rather than a nice-to-have. Because RMM agents are trusted by design, signature-based detection alone won't catch an attacker quietly riding a legitimate tool, making centralized audit logs, session recording, and alerts on anomalous activity — new admin accounts, off-hours logins, unfamiliar agent connections — essential to closing the loop.

Treating RMM as Part of the Attack Surface

For MSPs, the RMM platform is now part of the attack surface, and it needs to be defended with the same rigor as any client-facing asset. Solutions such as ManageEngine Endpoint Central MSP aim to address this gap directly, combining unified endpoint management with built-in security controls including role-based access, granular permissions, patch automation, and audit-ready activity logs — built specifically for MSPs managing distributed client fleets.

Key Takeaways

  • RMM abuse jumped 277% in 2025 and now accounts for 24% of all incidents observed by Huntress.
  • Attackers increasingly hijack legitimate RMM tools instead of building custom malware, driving a 53% decline in traditional hacking tool use.
  • A single compromised MSP RMM instance can expose dozens of downstream clients at once — one incident isolated 78 businesses.
  • Baseline hardening requires MFA on admin accounts, IP allow-listing, and removal of stale agents.
  • Role-based access control limits blast radius by preventing unnecessary domain-admin-level reach across clients.
  • Centralized logging and behavioral monitoring are essential since signature-based detection can't catch trusted tools being misused.
Tags: RMM Security Managed Service Providers Ransomware Endpoint Security Supply Chain Attacks Cybersecurity ManageEngine Access Control