The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB Environments
The Remote Access Blind Spot (TL-2026-2115) is a medium-severity tracked intrusion set, first published 2026-05-13. It has no confirmed attribution, affects N-able N-central, references 11 CVEs (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316), maps to 13 MITRE ATT&CK techniques (T1021.001, T1021.005, T1036), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-2115
- Threat ID
- TL-2026-2115
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-05-13
- Last reviewed
- 2026-05-13
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- msp, smb, technology, education, government administration, manufacturing, financial services, banking
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in The Remote Access Blind Spot
Malware and tooling: AnyDesk, Black Basta - S1070, Conti, LockBit, MeshAgent-derived custom implant, TeamViewer, Ultra VNC, mad liberator, AnyDesk, Atera, ConnectWise ScreenConnect, MeshAgent
Acronis' Threat Research Unit analyzed telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and found 63% run more than one RMM tool, with over a third running three or more, expanding the attack surface that ransomware crews and access brokers exploit by deploying legitimate or open-source RMM software (AnyDesk, ScreenConnect, TeamViewer, MeshAgent, RDP, VNC/UltraVNC) to blend in with trusted traffic.
How The Remote Access Blind Spot works
Acronis TRU's telemetry study of 1.8 million-plus endpoints running its RMM agent between January 2025 and March 2026 quantifies a structural SMB exposure: 63% of monitored endpoints run more than one remote monitoring and management tool, and over a third run three or more concurrently. The report identifies the most-abused tools as open-source or leaked-source-code utilities such as MeshAgent (whose public source lets threat actors recompile it into custom implants), plus ubiquitous protocols/tools RDP and VNC/UltraVNC. Because RMM traffic is functionally identical to legitimate IT-support activity and typically carries elevated, application-control-exempt privileges (MITRE ATT&CK T1219, 'commonly used as legitimate technical support software and may be allowed by application control'), it routinely evades anomaly-based network detection.
This is not a theoretical exposure. CISA/NSA/MS-ISAC documented the pattern as early as October 2022 in Advisory AA23-025A: phishing lures directed victims to help-desk-themed domains that delivered portable, no-install AnyDesk and ScreenConnect executables configured to phone home to actor-controlled RMM servers, initially for refund-scam fraud (MITRE T1657) and later as a template for broader intrusion tradecraft. That same tool-abuse pattern now underpins major ransomware operations: LockBit 3.0, Black Basta, and Akira affiliates routinely install AnyDesk, Splashtop, ScreenConnect, TeamViewer, Tactical RMM, and Pulseway post-compromise for persistent, low-noise access before deploying ransomware (Halcyon.ai tracks AnyDesk use by LockBit and Akira as recently as November 2025); one public LockBit case had affiliates exploit a Confluence RCE, pull AnyDesk via a Metasploit stager, and detonate ransomware within two hours. Scattered Spider layers this with help-desk-impersonation vishing/smishing to socially engineer IT staff into installing RMM tools directly, then uses that access for MFA-factor manipulation and lateral movement.
The underlying RMM platforms are themselves an active vulnerability surface. Acronis TRU's own 2025 tally — cited in this report — counts TeamViewer with 19 disclosed CVEs (two critical), N-able with 8, ConnectWise ScreenConnect with 2 additional CVEs (on top of the widely-exploited 2024 ScreenConnect auth-bypass/path-traversal chain, CVE-2024-1708/1709), and AnyDesk with 2, with every 2025 RMM platform vulnerability disclosure rated high or critical. Concretely: N-able N-central's CVE-2025-8875 (deserialization, CVSS 9.4) and CVE-2025-8876 (improper input validation, CVSS 9.4) were both added to CISA's KEV catalog after in-the-wild exploitation, with over 1,000 unpatched internet-exposed N-central instances identified; ConnectWise ScreenConnect's CVE-2025-3935 (ViewState code injection) was added to KEV in June 2025 after ConnectWise reported suspected nation-state activity against a subset of customers; TeamViewer's CVE-2025-0065 and CVE-2025-36537 are local privilege-escalation flaws in the Windows client/service that let an already-landed attacker jump to SYSTEM.
The net effect documented by Acronis is a compounding blind spot for resource-constrained SMBs and their MSPs: multiple overlapping RMM agents per endpoint increase both the exploitable surface (more vulnerable software to patch) and the living-off-the-land opportunity (more "legitimate" channels an attacker can hide inside), while the perceived legitimacy of RMM traffic suppresses the anomaly signals that would otherwise flag privilege escalation, lateral movement, and ransomware staging in progress.
MITRE ATT&CK techniques used in TL-2026-2115
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.005 VNC
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Credential Access
Initial Access
T1133 External Remote Services; T1566 Phishing
Execution
Persistence
T1547 Boot or Logon Autostart Execution
Resource Development
Impact
defense-impairment
Affected products and versions in The Remote Access Blind Spot
- N-able — N-central
Vulnerable versions: pre-Aug-2025 security release builds (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316); pre-Nov-2025 release builds (CVE-2025-11366, CVE-2025-11367)
Fixed in: Aug 2025 and later security releases - ConnectWise — ScreenConnect
Vulnerable versions: <= 25.2.3 (CVE-2025-3935); < 25.8 (CVE-2025-14265); versions affected by the 2024 CVE-2024-1708/CVE-2024-1709 auth-bypass/path-traversal chain
Fixed in: 25.2.4+ (CVE-2025-3935); 25.8+ (CVE-2025-14265) - TeamViewer — Full Client / Host (Windows)
Vulnerable versions: 11.x-15.x (CVE-2025-0065); < 15.67 (CVE-2025-36537)
Fixed in: current releases per TV-2025-1001/1002/1004 bulletins - AnyDesk — AnyDesk Client
Vulnerable versions: portable/silent-install builds abused via --install/--set-password command-line flags
Fixed in: N/A - abuse of legitimate product functionality, not a specific disclosed CVE - MeshCentral (open source) — MeshAgent
Vulnerable versions: open-source builds; public source enables recompilation into custom implants
Fixed in: N/A - abuse of open-source availability, not a patchable vulnerability
Remediation for The Remote Access Blind Spot
Patches
- ConnectWise ScreenConnect 25.2.4+ (CVE-2025-3935) and 25.8+ (CVE-2025-14265)
- N-able N-central Aug 2025 and subsequent security releases (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316, CVE-2025-11366, CVE-2025-11367)
- TeamViewer per security bulletins TV-2025-1001/1002/1004 (CVE-2025-0065, CVE-2025-36537, CVE-2025-41421)
Immediate actions
- Inventory and allow-list approved RMM tools per endpoint; alert on any RMM binary not on the approved list, cross-referencing the community LOLRMM catalog of known-abused tools
- Flag and investigate any endpoint running more than one RMM/remote-access tool simultaneously (Acronis TRU's own baseline: this is normal at 63% of SMB endpoints, so use deviation from the org's own approved set, not raw multiplicity, as the trigger)
- Block outbound connections to known help-desk-scam RMM distribution domains (see IOCs) and enforce EDR execution blocking on unauthorized portable RMM installers
- Patch N-able N-central, ConnectWise ScreenConnect, TeamViewer, and AnyDesk to current versions immediately to close CVE-2025-8875/8876/9316/11366/11367, CVE-2025-3935/14265, and CVE-2025-0065/36537
Workarounds
- Restrict RMM console access to VPN/allow-listed source IPs where immediate patching is not possible
- Disable unattended-access and auto-start-with-Windows features on RMM clients not actively required for IT operations
Longer-term hardening
- Require MFA and conditional access on every RMM/remote-access console, and require verified callback procedures before help desks action remote-access or password-reset requests
- Segment MSP/RMM management traffic onto its own network zone, separate from general user and production segments
- Deploy behavioral EDR detections for RMM-specific silent-install command lines (e.g., AnyDesk.exe --install --start-with-win --set-password) rather than relying on domain/signature reputation alone
- Treat RMM traffic as a monitored, not inherently trusted, channel; baseline expected RMM vendor/destination pairs per endpoint and alert on new ones
CVEs associated with The Remote Access Blind Spot
CVE-2025-8875, CVE-2025-8876, CVE-2025-9316, CVE-2025-11366, CVE-2025-11367, CVE-2025-3935, CVE-2025-14265, CVE-2025-0065, CVE-2025-36537, CVE-2024-1708, CVE-2024-1709
Weaknesses (CWE) in The Remote Access Blind Spot
CWE-502, CWE-20, CWE-77, CWE-269, CWE-287
Timeline of The Remote Access Blind Spot
- CISA/NSA later document an October 2022 phishing campaign in which actors used help-desk-themed lures to deliver portable AnyDesk and ScreenConnect executables for bank-refund scams — the earliest widely-cited case of RMM software weaponized as first-stage malware.
- CISA, NSA, and MS-ISAC publish Advisory AA23-025A, 'Protecting Against Malicious Use of RMM Software,' formalizing IOCs and mitigations for the RMM-abuse pattern.
- ConnectWise discloses CVE-2024-1708 and CVE-2024-1709 (ScreenConnect authentication-bypass/path-traversal chain), rapidly weaponized by LockBit and Black Basta affiliates for mass exploitation.
- A high-severity TeamViewer Windows client privilege-escalation flaw, CVE-2025-0065, is disclosed and patched (H-ISAC advisory).
- LockBit 3.0 affiliates are reported exploiting a Confluence RCE for initial access, then deploying AnyDesk via Metasploit stagers and detonating ransomware within roughly two hours of compromise.
- CISA adds ConnectWise ScreenConnect CVE-2025-3935 (ViewState code injection, actively exploited, suspected nation-state activity against a subset of customers) to the Known Exploited Vulnerabilities catalog.
- N-able discloses CVE-2025-8875 (deserialization) and CVE-2025-8876 (improper input validation) in N-central, both CVSS 9.4 and exploited in the wild; over 1,000 unpatched internet-exposed instances identified.
- Halcyon.ai TTP tracking marks its most recent confirmed sightings (November 2025) of LockBit and Akira affiliates using AnyDesk for post-compromise remote access.
- Acronis TRU's full-year 2025 RMM vulnerability tally feeding this report closes out: TeamViewer 19 CVEs (2 critical), N-able 8, ConnectWise ScreenConnect +2, AnyDesk +2 — every one rated high or critical.
- Acronis TRU publishes 'The remote access blind spot,' analyzing telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and finding 63% run multiple RMM tools, over a third running three or more.
Sources cited for The Remote Access Blind Spot
- The remote access blind spot: An analysis of RMM tool risk for SMBs
- Phishing-to-RMM Attacks: The Blind Spot CISOs Need to Close
- Alert (AA23-025A): Protecting Against Malicious Use of Remote Monitoring and Management Software
- AnyDesk in Ransomware Operations: IOC & TTP Index
- Vulnerabilities in MSP-friendly RMM solution exploited in the wild (CVE-2025-8875, CVE-2025-8876)
- CVE-2025-36537: TeamViewer Privilege Escalation Vulnerability
- Remediation and Hardening Guide for ConnectWise ScreenConnect Vulnerabilities (CVE-2024-1708 and CVE-2024-1709)
- ConnectWise ScreenConnect Command Injection Vulnerability Added to CISA KEV (CVE-2025-3935)
- LOLRMM: A Unified Approach to RMM Software Tracking
- Scattered Spider (Joint Cybersecurity Advisory Update)
More in threat intel
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
Detection coverage for TL-2026-2115
As of 2026-05-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2115 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.