A Series of Unfortunate (RMM) Events
Essential information
- Published
- 19/12/2025 18:30
- Modified
- 21/12/2025 23:06
- Tags
- 2025-12-19 goto resolve multiple rmm tools pdq persistence phishing rmm abuse screenconnect simplehelp social engineering
- Related entities
- 2 techniques (mitre), 9 others
Description
Series of Unfortunate Events
Summary: This analysis examines the increasing trend of threat actors abusing Remote Monitoring and Management (RMM) tools in their attacks. The report highlights a specific pattern where attackers use PDQ or GoTo Resolve to deploy secondary RMM tools like ScreenConnect or SimpleHelp. Multiple examples are provided, including a real estate company compromised through a phishing email, an investment firm attacked via a malicious download, and a car dealer targeted through multiple RMM installations. The report also discusses various social engineering lures used by attackers, such as holiday-themed messages and fake bid transcripts. It emphasizes the importance of a managed Security Operations Center (SOC) in detecting and mitigating these threats, and provides recommendations for businesses to prevent RMM abuse.