Microsoft Threat Intelligence Podcast

← Microsoft Threat Intelligence Podcast9 sep · 28 min

Why Threat Actors Love Your RMM

Why Threat Actors Love Your RMM9 sep28 min

In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress. 

They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft. 

In this episode you’ll learn:      

How AI is making phishing lures and fake websites more convincing 

Why trusted remote-access software can evade traditional endpoint detection 

How security teams can identify and block unauthorized RMM activity 

Some questions we ask:     

What information are attackers looking for once they gain access? 

Why are attackers choosing legitimate tools instead of traditional malware? 

How does compromised access eventually lead to ransomware or data theft? 

 

Resources: