The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB Environments — Threadlinqs Intelligence
As of 2026-05-13, The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB Environments is a medium-severity threat intel threat attributed to Multiple ransomware, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-2115 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple ransomware · FINANCIAL
Acronis' Threat Research Unit analyzed telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and found 63% run more than one RMM tool, with over a third running three or more, expanding the attack
Acronis TRU's telemetry study of 1.8 million-plus endpoints running its RMM agent between January 2025 and March 2026 quantifies a structural SMB exposure: 63% of monitored endpoints run more than one remote monitoring and management tool, and over a third run three or more concurrently. The report identifies the most-abused tools as open-source or leaked-source-code utilities such as MeshAgent (whose public source lets threat actors recompile it into custom implants), plus ubiquitous protocols/tools RDP and VNC/UltraVNC. Because RMM traffic is functionally identical to legitimate IT-support activity and typically carries elevated, application-control-exempt privileges (MITRE ATT&CK T1219, 'commonly used as legitimate technical support software and may be allowed by application control'), it routinely evades anomaly-based network detection.
This is not a theoretical exposure. CISA/NSA/MS-ISAC documented the pattern as early as October 2022 in Advisory AA23-025A: phishing lures directed victims to help-desk-themed domains that delivered portable, no-install AnyDesk and ScreenConnect executables configured to phone home to actor-controlled RMM servers, initially for refund-scam fraud (MITRE T1657) and later as a template for broader intrusion tradecraft. That same tool-abuse pattern now underpins major ransomware operations: LockBit 3.0, Black Basta, and Akira affiliates routinely install AnyDesk, Splashtop, ScreenConnect, TeamViewer, Tactical RMM, and Pulseway post-compromise for persistent, low-noise access before deploying ransomware (Halcyon.ai tracks AnyDesk use by LockBit and Akira as recently as November 2025); one public LockBit case had affiliates exploit a Confluence RCE, pull AnyDesk via a Metasploit stager, and detonate ransomware within two hours. Scattered Spider layers this with help-desk-impersonation vishing/smishing to socially engineer IT staff into installing RMM tools directly, then uses that access for MFA-factor manipulation and lateral movement.
The underlying RMM platforms are themselves an active vulnerability surface. Acronis TRU's own 2025 tally — cited in this report — counts TeamViewer with 19 disclosed CVEs (two critical), N-able with 8, ConnectWise ScreenConnect with 2 additional CVEs (on top of the widely-exploited 2024 ScreenConnect auth-bypass/path-traversal chain, CVE-2024-1708/1709), and AnyDesk with 2, with every 2025 RMM platform vulnerability disclosure rated high or critical. Concretely: N-able N-central's CVE-2025-8875 (deserialization, CVSS 9.4) and CVE-2025-8876 (improper input validation, CVSS 9.4) were both added to CISA's KEV catalog after in-the-wild exploitation, with over 1,000 unpatched internet-exposed N-central instances identified; ConnectWise ScreenConnect's CVE-2025-3935 (ViewState code injection) was added to KEV in June 2025 after ConnectWise reported suspected nation-state activity against a subset of customers; TeamViewer's CVE-2025-0065 and CVE-2025-36537 are local privilege-escalation flaws in the Windows client/service that let an already-landed attacker jump to SYSTEM.
The net effect documented by Acronis is a compounding blind spot for resource-constrained SMBs and their MSPs: multiple overlapping RMM agents per endpoint increase both the exploitable surface (more vulnerable software to patch) and the living-off-the-land opportunity (more "legitimate" channels an attacker can hide inside), while the perceived legitimacy of RMM traffic suppresses the anomaly signals that would otherwise flag privilege escalation, lateral movement, and ransomware staging in progress.
Weaknesses (CWE)
CWE-502, CWE-20, CWE-77, CWE-269, CWE-287
Target sectors: msp, smb, technology, education, government administration, manufacturing, financial services, banking
Target regions: North America, Europe, australia
Timeline
- CISA/NSA later document an October 2022 phishing campaign in which actors used help-desk-themed lures to deliver portable AnyDesk and ScreenConnect executables for bank-refund scams — the earliest widely-cited case of RMM software weaponized as first-stage malware.
- CISA, NSA, and MS-ISAC publish Advisory AA23-025A, 'Protecting Against Malicious Use of RMM Software,' formalizing IOCs and mitigations for the RMM-abuse pattern.
- ConnectWise discloses CVE-2024-1708 and CVE-2024-1709 (ScreenConnect authentication-bypass/path-traversal chain), rapidly weaponized by LockBit and Black Basta affiliates for mass exploitation.
- A high-severity TeamViewer Windows client privilege-escalation flaw, CVE-2025-0065, is disclosed and patched (H-ISAC advisory).
- LockBit 3.0 affiliates are reported exploiting a Confluence RCE for initial access, then deploying AnyDesk via Metasploit stagers and detonating ransomware within roughly two hours of compromise.
- CISA adds ConnectWise ScreenConnect CVE-2025-3935 (ViewState code injection, actively exploited, suspected nation-state activity against a subset of customers) to the Known Exploited Vulnerabilities catalog.
- N-able discloses CVE-2025-8875 (deserialization) and CVE-2025-8876 (improper input validation) in N-central, both CVSS 9.4 and exploited in the wild; over 1,000 unpatched internet-exposed instances identified.
- Halcyon.ai TTP tracking marks its most recent confirmed sightings (November 2025) of LockBit and Akira affiliates using AnyDesk for post-compromise remote access.
- Acronis TRU's full-year 2025 RMM vulnerability tally feeding this report closes out: TeamViewer 19 CVEs (2 critical), N-able 8, ConnectWise ScreenConnect +2, AnyDesk +2 — every one rated high or critical.
- Acronis TRU publishes 'The remote access blind spot,' analyzing telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and finding 63% run multiple RMM tools, over a third running three or more.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, CVE-2025-8875, CVE-2025-8876, CVE-2025-9316, CVE-2025-11366, CVE-2025-11367, CVE-2025-3935, CVE-2025-14265, CVE-2025-0065, CVE-2025-36537, CVE-2024-1708, T1583.001, T1566, T1133, T1204.002, T1547, T1036, T1685, T1110.004, T1021.001, T1021.005