Listen to this Post
Introduction: The Trusted Tools Becoming Cybercriminals’ Favorite Weapons
Cybersecurity defenders have spent years teaching organizations to watch for suspicious files, malicious links, unknown software, and unusual network activity. Yet many modern attacks do not begin with an obviously dangerous program. Instead, attackers increasingly rely on legitimate remote access tools—the same software trusted by IT teams to support employees, manage devices, troubleshoot systems, and maintain infrastructure.
This shift creates a difficult security problem. When a remote monitoring and management (RMM) application is legitimate, digitally signed, and widely used across the industry, traditional security tools may not immediately treat it as a threat. The software itself may be harmless, but the person controlling it may not be.
Cybersecurity vendor Huntress is responding to that challenge by making a new application-control capability, called RMM Guard, available to its entire customer base at no additional cost. The announcement comes as Huntress reports a dramatic 277% increase in RMM-related attacks over the past year, highlighting how quickly legitimate remote administration software is becoming part of the modern attack chain.
The company says its new capability can identify remote access tools operating across an environment and automatically block those that have not been explicitly authorized. Rather than requiring small IT teams to build massive application allow-lists from the ground up, Huntress is taking a narrower and more practical approach: begin with the software categories attackers abuse most often, then expand protection over time.
For managed service providers (MSPs), small and midsize businesses, and security teams operating with limited staff, the move could make application control more accessible at a time when attackers are increasingly hiding behind trusted technology.
Original Summary: Huntress Expands RMM Guard to All Customers
A Free Security Capability for Every Huntress Customer
Huntress has announced that RMM Guard is now available to all customers and partners with a Huntress agent deployed, without an additional charge. The capability was previously limited by subscription requirements and operated primarily in a learning mode.
The new availability removes those restrictions and gives organizations a way to monitor and control remote access software across their environments.
Blocking Unauthorized Remote Access Software
RMM Guard inventories remote monitoring and management tools running throughout an organization’s systems. It then identifies which tools are approved and can automatically block those that have not been authorized.
This includes attacker-controlled installations of legitimate software, such as unauthorized instances of ScreenConnect or other remote administration platforms.
RMM Attacks Increased by 277%
According to Huntress, attacks involving RMM tools rose by 277% during the past year. The company also reported that approximately one-third of the incidents its analysts observed so far this year might have been prevented if unauthorized RMM software had been blocked before it could run.
These figures suggest that remote access software is no longer simply an operational tool. It has become a major security boundary.
Phishing Campaigns Are Delivering Legitimate RMM Tools
Huntress cited an incident involving a phishing email disguised as a notification about a “pay increase.” The message persuaded an employee to install LogMeIn Resolve, giving an attacker remote access to the organization.
The activity was eventually detected through endpoint monitoring and Huntress’s 24/7 Security Operations Centre, but the case demonstrated how a trusted application can become an attacker’s entry point.
Managed ESPM Remains in Early Access
RMM Guard is part of Huntress’s broader Managed Endpoint Security Posture Management (ESPM) platform, which remains in early access.
Existing customers can request access to the ESPM early-access program through their Huntress account manager while the company prepares the wider commercial release.
Why RMM Tools Have Become a Growing Cybersecurity Risk
Remote Management Software Is Designed for Powerful Access
RMM platforms are built to give administrators deep visibility and control over endpoints. Depending on the product and configuration, they may allow operators to view screens, control keyboards and mice, transfer files, execute commands, deploy software, manage services, and access devices from remote locations.
Those capabilities are valuable for legitimate IT operations. They are also extremely valuable to attackers.
A criminal who successfully installs an RMM agent may not need to deploy a custom backdoor immediately. The remote access software can already provide many of the functions normally associated with malware.
Legitimate Software Can Blend Into Normal Activity
Security tools often rely on reputation, signatures, behavior, and known indicators of compromise. A well-known RMM application may be digitally signed and commonly used by businesses, making it more difficult to classify as malicious based only on its presence.
This creates an important distinction:
The software may be legitimate, while the deployment and operator are unauthorized.
Traditional detection systems may ask, “Is this program malicious?” Application control asks a different question:
“Is this program supposed to be running here?”
That second question can be far more effective when attackers abuse trusted software.
Attackers Benefit From “Living Off the Land”
The use of legitimate tools is part of a broader technique often described as living off the land. Instead of relying entirely on custom malware, attackers use approved applications, built-in operating system utilities, administrative tools, cloud services, and remote management platforms.
This approach can reduce the attacker’s need to develop and maintain malware. It may also make investigations more difficult because suspicious activity can resemble ordinary administrative work.
Remote Access Can Create Long-Term Persistence
Once an attacker installs and configures an RMM tool, they may be able to reconnect even after the original phishing session ends.
Depending on the platform and permissions involved, remote access software may provide:
Persistent access to a compromised device
Remote command execution
File upload and download capabilities
Screen monitoring and interactive control
Access to additional systems
A channel for deploying ransomware or data-stealing tools
The initial installation may therefore be only the beginning of the attack.
Application Control: Preventing Unauthorized Software Before It Runs
The Security Model Behind Allow-Listing
Application control—often called allow-listing—uses a prevention-first model. Instead of waiting for security software to identify malicious behavior, the system permits only approved applications, files, publishers, or software categories to execute.
The basic principle is simple:
Known and authorized software is allowed. Unknown or unauthorized software is blocked.
In theory, this can reduce the attack surface significantly. If an attacker cannot execute an unauthorized remote access tool, the attack may fail before remote control is established.
Why Traditional Application Control Can Be Difficult
Despite its security benefits, application control has historically been difficult to deploy.
Large organizations may spend months creating software inventories, building policies, testing business applications, handling exceptions, and rolling out enforcement in phases. A poorly designed policy can block legitimate business software and interrupt operations.
For smaller organizations, those requirements can be unrealistic.
An MSP may manage hundreds or thousands of endpoints across multiple customers, each with different applications and workflows. A small internal IT team may not have the staff required to maintain a detailed allow-list for every executable in the environment.
Huntress Is Focusing on High-Risk Software Categories
Huntress is attempting to reduce that complexity by avoiding an immediate “approve every application” model.
Instead, the company plans to focus on software categories that attackers frequently abuse. RMM tools are the first major category, with potential expansion into areas such as:
Artificial intelligence applications
File-sharing tools
Remote access platforms
Other high-risk software categories
This category-based approach could provide meaningful security benefits without forcing smaller teams to build a complete application-control program from scratch.
The “Pay Increase” Phishing Example
Social Engineering Remains the First Step
The phishing example cited by Huntress is notable because the lure was not highly technical. It used a subject designed to attract attention and create an emotional response: a possible pay increase.
Attackers often choose themes connected to money, promotions, benefits, invoices, urgent requests, or workplace changes because employees are more likely to open messages involving personally relevant topics.
A Legitimate Tool Was Used as the Payload
Instead of delivering obvious malware, the phishing campaign led the employee to install LogMeIn Resolve, a legitimate remote support and management platform.
This technique can be particularly effective because the software may appear trustworthy. The installation may not trigger the same warnings associated with an unknown executable.
Endpoint Monitoring Provided the Final Safety Layer
Huntress reported that the activity was detected through endpoint monitoring and its 24/7 Security Operations Centre.
The incident illustrates why layered security remains important. Application control may prevent unauthorized software from running, but endpoint detection, monitoring, identity security, email protection, and human awareness are still necessary.
No single control can reliably stop every attack.
Deep Analysis: How RMM Guard Could Change Endpoint Defense
The Security Boundary Is Shifting
For years, endpoint security focused heavily on identifying malicious code. That approach remains essential, but modern attacks increasingly involve legitimate tools used in unauthorized ways.
The new security boundary is not simply “malicious versus harmless.” It is increasingly:
Authorized versus unauthorized.
An approved RMM platform used by an internal IT administrator may be normal. The same application installed through a phishing campaign and connected to an external attacker is a serious incident.
Inventory Is the Foundation of Control
Organizations cannot protect what they cannot see.
A complete inventory of remote access software can reveal:
Unapproved RMM agents
Duplicate remote management tools
Legacy tools that were never removed
Shadow IT deployments
Unauthorized remote support applications
Software installed by attackers
Many organizations may discover that they have more remote access tools than expected.
Default-Deny Can Be Powerful When Applied Carefully
A full default-deny application-control strategy can be difficult to manage. However, applying the concept to a specific high-risk category may offer a more practical balance.
For example:
Review installed applications related to remote access
Get-ItemProperty `
HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\,
HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ |
Where-Object {
$_.DisplayName -match "Remote|Screen|Connect|Support|RMM|LogMeIn"
} |
Select-Object DisplayName, DisplayVersion, Publisher
This command can help administrators review installed software that may be associated with remote access. Results should be validated carefully because naming patterns alone cannot determine whether an application is authorized or malicious.
Review Running Processes
Administrators can also inspect active processes:
Get-Process | Sort-Object ProcessName | Select-Object ProcessName, Id, Path
A process inventory can help identify unexpected executables, but legitimate processes may use unfamiliar names. Investigation should include publisher information, installation paths, network activity, and organizational approval status.
Check Active Network Connections
Remote access tools often maintain outbound connections to cloud infrastructure or relay services.
Get-NetTCPConnection |
Where-Object {$_.State -eq "Established"} |
Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, OwningProcess
Security teams should correlate network connections with processes rather than assuming that every external connection is malicious.
Identify Services That May Provide Persistence
Some RMM products install Windows services to support unattended access.
Get-CimInstance Win32_Service | Select-Object Name, DisplayName, State, StartMode, PathName |
Sort-Object DisplayName
Unexpected services should be reviewed against approved software inventories.
Application Control Must Avoid Business Disruption
Blocking software without testing can create operational problems. A legitimate support platform may be required for remote workers, third-party vendors, or emergency IT response.
A safer deployment process includes:
Inventory existing remote access software.
Identify approved products and publishers.
Monitor activity before enforcing blocks.
Test policies with a limited group.
Create an exception process.
Expand enforcement gradually.
Review alerts and blocked activity regularly.
The goal is not to block every unfamiliar program. The goal is to prevent unauthorized remote control while preserving legitimate business operations.
What Undercode Say:
The Rise of RMM Abuse Is a Warning About Trust
RMM abuse is growing because attackers understand that trusted software can bypass assumptions built into traditional security programs.
The threat is not necessarily the RMM product itself.
The threat is unauthorized installation, unauthorized configuration, and unauthorized control.
Organizations must stop treating software reputation as proof of safety.
A legitimate digital signature does not prove that a deployment is authorized.
A well-known vendor does not guarantee that the operator is trustworthy.
A remote access tool can be safe in one environment and dangerous in another.
Context is now one of the most important security signals.
Huntress’s reported 277% increase shows that this is not a minor trend.
Attackers are actively incorporating RMM platforms into phishing and intrusion campaigns.
The technique reduces the need for custom malware.
It can also provide persistence with tools administrators already understand.
That makes RMM abuse efficient for attackers.
It also makes detection more complicated for defenders.
Traditional antivirus may see a legitimate application.
Security analysts must determine who installed it and why.
That investigation can take time.
Application control can reduce the need for repeated investigation.
If the organization never approved a tool, the software can be blocked before it becomes an access channel.
This is a stronger security position than waiting for malicious behavior.
Prevention can be cheaper than incident response.
It can also reduce the opportunity for attackers to move laterally.
The decision to provide RMM Guard without an additional charge is strategically important.
Smaller organizations often lack dedicated application-control teams.
MSPs face the challenge of managing many customer environments.
Complex security products are frequently underused.
A focused control may be easier to deploy.
A category-based model may also reduce policy maintenance.
Starting with RMM tools is logical because they provide high-value access.
Future expansion into AI applications could become equally important.
AI tools may introduce data exposure and shadow IT risks.
File-sharing applications can also create unauthorized data-transfer channels.
The larger vision appears to be security posture management through controlled software categories.
That approach could make endpoint protection more accessible.
However, implementation quality will determine its long-term value.
False positives could create operational friction.
Weak policy management could leave gaps.
Organizations will still need accurate software inventories.
They will also need clear approval processes.
Security teams should not assume that one control eliminates phishing risk.
Email filtering remains essential.
Endpoint detection remains essential.
Identity protection remains essential.
User awareness remains essential.
The strongest defense will combine prevention with continuous monitoring.
RMM Guard may help close a dangerous gap.
But its real value will depend on how consistently organizations define and enforce authorization.
The most important lesson is simple:
Trusted software is not automatically trusted activity.
✅ Huntress Reported a 277% Increase in RMM-Related Attacks
The article states that Huntress observed a 277% increase in attacks involving RMM tools over the past year. This figure is presented as Huntress’s own threat intelligence and should be understood as a measurement from the company’s visibility and customer environment rather than a universal estimate for every organization.
✅ Unauthorized RMM Software Can Create Serious Security Risks
Legitimate remote management tools can provide persistent access, remote control, file transfer, and administrative capabilities. If an attacker installs or controls such software, the tool can become an effective channel for unauthorized access.
✅ Application Control Can Prevent Unauthorized Software Execution
Allow-listing and application-control systems can reduce risk by preventing unapproved software from running. Their effectiveness depends on accurate policies, complete inventories, controlled exceptions, and careful deployment.
✅ The “Pay Increase” Phishing Example Matches a Common Attack Pattern
Cybercriminals frequently use financially relevant or workplace-related themes to encourage employees to open messages and follow instructions. A pay-related lure is consistent with common social-engineering tactics.
⚠️ One-Third of Incidents Being Preventable Is Context-Specific
The claim that roughly one-third of observed incidents could have been prevented by blocking unauthorized RMM tools reflects Huntress’s analysis of incidents within its visibility. It should not automatically be applied to every industry or organization without additional independent data.
Prediction
(+1) Application Control Will Move From Enterprise Luxury to Mainstream Security
Over the next several years, application control is likely to become more automated, category-based, and accessible to smaller organizations.
Security vendors will increasingly focus on preventing unauthorized use of trusted applications rather than only detecting known malware.
RMM platforms are likely to remain a high-priority category because they provide attackers with immediate operational access.
More endpoint security products may introduce automatic discovery of remote access tools.
Organizations may begin maintaining formal lists of approved RMM providers.
Unauthorized remote management software could become a standard alert category in security operations centers.
AI applications may become the next major category for policy-based control.
File-sharing platforms may follow as organizations attempt to reduce data exposure.
MSPs may benefit from centralized policies that can be adapted across multiple customers.
Attackers will likely respond by changing installation methods and abusing approved tools.
This will create an ongoing contest between authorization controls and social engineering.
The strongest organizations will combine application control with identity protection, endpoint monitoring, email security, and continuous threat hunting.
Huntress’s decision to make RMM Guard broadly available may accelerate that transition.
The future of endpoint security may depend less on asking whether software is malicious—and more on proving whether it belongs.
▶️ Related Video (80% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.itsecurityguru.org
Extra Source Hub (Possible Sources for article):
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




