Remote monitoring and management (RMM) platforms sit at the core of every managed service provider's operations — and that's precisely why attackers have turned them into a favorite weapon. Rather than building custom malware, threat actors are increasingly hijacking legitimate RMM agents already trusted inside client environments, using them as a single control point for command-and-control, lateral movement, and ransomware deployment.
A Sharp Shift in Attacker Tactics
The use of traditional hacking tools plummeted by 53% as cybercriminals instead built entire playbooks around RMM tools to drop malware, steal credentials, and execute commands. The Huntress 2026 Cyber Threat Report recorded a 277% jump in RMM abuse during 2025, with RMM abuse now accounting for 24% of all incidents the company observed.
Other vendors reported similar patterns. 30% of the security incidents Blackpoint Cyber responded to involved RMM software abuse, with CAPTCHA and ClickFix scams driving 58% of malicious activity detected. Separately, RMM tool abuse was found to be the single biggest endpoint threat in one analysis, accounting for 26% of all detections, with tools such as ScreenConnect, AteraAgent, and MeshAgent used to gain unauthorized access.
Why MSPs Face an Amplified Risk
The risk to MSPs is amplified by their very structure: one compromised RMM instance can mean access to dozens of downstream clients simultaneously. When attackers compromise an RMM solution managed by an MSP, they can immediately access multiple downstream customers in a massive supply chain attack.
A recent real-world example bore this out when an attack on an MSP led to the mass isolation of 78 businesses and subsequent exploitation across four downstream customers.
"Stealing credentials and abusing tools already trusted in the environment is easier than finding a zero-day exploit in an appliance."— Threat Intelligence Engineer
Treating RMM as Part of the Attack Surface
For MSPs, the RMM platform is now part of the attack surface, and it needs to be defended with the same rigor as any client-facing asset. Solutions such as ManageEngine Endpoint Central MSP aim to address this gap directly, combining unified endpoint management with built-in security controls including role-based access, granular permissions, patch automation, and audit-ready activity logs — built specifically for MSPs managing distributed client fleets.
