RMM Tools: A Double-Edged Sword for MSPs

Garry BloomGarry Bloom · Founder & CEO
8 May 2026
5 min read
PhishingAttack
ITSecurity
ThreatIntelligence
RMM
MSP
Cybersecurity

Legitimate remote monitoring tools are being weaponized by threat actors—and it's happening more than you think.

The VENOMOUS#HELPER campaign has impacted 80+ organizations by abusing SimpleHelp and ScreenConnect RMM platforms. What makes this particularly dangerous:

  • No traditional malware – attackers rely solely on legitimately signed RMM tools to evade detection

  • Dual persistence – using TWO RMM tools ensures backup access if one is discovered

  • 277% YoY increase in RMM tool abuse while traditional hacking tool use dropped 53%

  • Blends with normal operations – RMM activity rarely triggers security alerts since IT teams use these tools daily

The attack starts with phishing emails impersonating the US Social Security Administration, targeting employees with access to sensitive systems or crypto assets.

What MSPs Need to Do Now

  • Implement application whitelisting to prevent unauthorized RMM installations

  • Enable detailed endpoint logging with strong SIEM/EDR monitoring

  • Foster "cyber paranoia" through security awareness training—especially for C-suite and non-technical staff

  • Monitor for unauthorized RMM tool installations across your client environments

As MSP professionals, we need to be vigilant about the very tools we trust. What controls do you have in place to prevent unauthorized RMM deployments?

#Cybersecurity #MSP #RMM #ThreatIntelligence #ITSecurity #PhishingAttack

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
8 May 2026
5 min read
PhishingAttack
ITSecurity
ThreatIntelligence
RMM
MSP
Cybersecurity

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Critical Windows VPN Flaw Under Active Attack: What Perth Businesses Need to Check

CISA confirms hackers are actively exploiting a critical Windows VPN flaw, CVE-2026-33824, to break into business networks with no login required. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Scams Awareness Week 2026: Why 4 in 5 Perth Small Businesses Are Already a Target

This week's national Scams Awareness Week data shows four in five small businesses were targeted in the past year. Here's the 'Stop. Check. Protect.' test for your Perth business. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Windows 11 24H2 Stops Getting Updates in October: What Perth Businesses Should Check Now

Windows 11 version 24H2 Home and Pro editions reach end of updates on 13 October 2026. Here's how to check what your Perth business is running and what to do before then. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
When a ‘Legit’ Support Call Steals Your Login Session
CyberSecurity
ITSupportPerth

When a ‘Legit’ Support Call Steals Your Login Session

MFA was enabled — but a fake Xero support call led to a stolen browser session, email takeover, and full lockout. Learn how to prevent it with least privilege, Conditional Access, and phishing-resistant policies.

5 min read
1/30/2026
Call us