The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB Environments

The Remote Access Blind Spot (TL-2026-2115) is a medium-severity tracked intrusion set, first published 2026-05-13. It has no confirmed attribution, affects N-able N-central, references 11 CVEs (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316), maps to 13 MITRE ATT&CK techniques (T1021.001, T1021.005, T1036), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-2115

Threat ID
TL-2026-2115
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-05-13
Last reviewed
2026-05-13
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
msp, smb, technology, education, government administration, manufacturing, financial services, banking
Target regions
North America, Europe, australia
Detection rules
9
Indicators of compromise
22

Malware and tooling in The Remote Access Blind Spot

Malware and tooling: AnyDesk, Black Basta - S1070, Conti, LockBit, MeshAgent-derived custom implant, TeamViewer, Ultra VNC, mad liberator, AnyDesk, Atera, ConnectWise ScreenConnect, MeshAgent

Acronis' Threat Research Unit analyzed telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and found 63% run more than one RMM tool, with over a third running three or more, expanding the attack surface that ransomware crews and access brokers exploit by deploying legitimate or open-source RMM software (AnyDesk, ScreenConnect, TeamViewer, MeshAgent, RDP, VNC/UltraVNC) to blend in with trusted traffic.

How The Remote Access Blind Spot works

Acronis TRU's telemetry study of 1.8 million-plus endpoints running its RMM agent between January 2025 and March 2026 quantifies a structural SMB exposure: 63% of monitored endpoints run more than one remote monitoring and management tool, and over a third run three or more concurrently. The report identifies the most-abused tools as open-source or leaked-source-code utilities such as MeshAgent (whose public source lets threat actors recompile it into custom implants), plus ubiquitous protocols/tools RDP and VNC/UltraVNC. Because RMM traffic is functionally identical to legitimate IT-support activity and typically carries elevated, application-control-exempt privileges (MITRE ATT&CK T1219, 'commonly used as legitimate technical support software and may be allowed by application control'), it routinely evades anomaly-based network detection.

This is not a theoretical exposure. CISA/NSA/MS-ISAC documented the pattern as early as October 2022 in Advisory AA23-025A: phishing lures directed victims to help-desk-themed domains that delivered portable, no-install AnyDesk and ScreenConnect executables configured to phone home to actor-controlled RMM servers, initially for refund-scam fraud (MITRE T1657) and later as a template for broader intrusion tradecraft. That same tool-abuse pattern now underpins major ransomware operations: LockBit 3.0, Black Basta, and Akira affiliates routinely install AnyDesk, Splashtop, ScreenConnect, TeamViewer, Tactical RMM, and Pulseway post-compromise for persistent, low-noise access before deploying ransomware (Halcyon.ai tracks AnyDesk use by LockBit and Akira as recently as November 2025); one public LockBit case had affiliates exploit a Confluence RCE, pull AnyDesk via a Metasploit stager, and detonate ransomware within two hours. Scattered Spider layers this with help-desk-impersonation vishing/smishing to socially engineer IT staff into installing RMM tools directly, then uses that access for MFA-factor manipulation and lateral movement.

The underlying RMM platforms are themselves an active vulnerability surface. Acronis TRU's own 2025 tally — cited in this report — counts TeamViewer with 19 disclosed CVEs (two critical), N-able with 8, ConnectWise ScreenConnect with 2 additional CVEs (on top of the widely-exploited 2024 ScreenConnect auth-bypass/path-traversal chain, CVE-2024-1708/1709), and AnyDesk with 2, with every 2025 RMM platform vulnerability disclosure rated high or critical. Concretely: N-able N-central's CVE-2025-8875 (deserialization, CVSS 9.4) and CVE-2025-8876 (improper input validation, CVSS 9.4) were both added to CISA's KEV catalog after in-the-wild exploitation, with over 1,000 unpatched internet-exposed N-central instances identified; ConnectWise ScreenConnect's CVE-2025-3935 (ViewState code injection) was added to KEV in June 2025 after ConnectWise reported suspected nation-state activity against a subset of customers; TeamViewer's CVE-2025-0065 and CVE-2025-36537 are local privilege-escalation flaws in the Windows client/service that let an already-landed attacker jump to SYSTEM.

The net effect documented by Acronis is a compounding blind spot for resource-constrained SMBs and their MSPs: multiple overlapping RMM agents per endpoint increase both the exploitable surface (more vulnerable software to patch) and the living-off-the-land opportunity (more "legitimate" channels an attacker can hide inside), while the perceived legitimacy of RMM traffic suppresses the anomaly signals that would otherwise flag privilege escalation, lateral movement, and ransomware staging in progress.

MITRE ATT&CK techniques used in TL-2026-2115

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.005 VNC

Defense Evasion

T1036 Masquerading

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Credential Access

T1110.004 Credential Stuffing

Initial Access

T1133 External Remote Services; T1566 Phishing

Execution

T1204.002 Malicious File

Persistence

T1547 Boot or Logon Autostart Execution

Resource Development

T1583.001 Domains

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in The Remote Access Blind Spot

  • N-able — N-central
    Vulnerable versions: pre-Aug-2025 security release builds (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316); pre-Nov-2025 release builds (CVE-2025-11366, CVE-2025-11367)
    Fixed in: Aug 2025 and later security releases
  • ConnectWise — ScreenConnect
    Vulnerable versions: <= 25.2.3 (CVE-2025-3935); < 25.8 (CVE-2025-14265); versions affected by the 2024 CVE-2024-1708/CVE-2024-1709 auth-bypass/path-traversal chain
    Fixed in: 25.2.4+ (CVE-2025-3935); 25.8+ (CVE-2025-14265)
  • TeamViewer — Full Client / Host (Windows)
    Vulnerable versions: 11.x-15.x (CVE-2025-0065); < 15.67 (CVE-2025-36537)
    Fixed in: current releases per TV-2025-1001/1002/1004 bulletins
  • AnyDesk — AnyDesk Client
    Vulnerable versions: portable/silent-install builds abused via --install/--set-password command-line flags
    Fixed in: N/A - abuse of legitimate product functionality, not a specific disclosed CVE
  • MeshCentral (open source) — MeshAgent
    Vulnerable versions: open-source builds; public source enables recompilation into custom implants
    Fixed in: N/A - abuse of open-source availability, not a patchable vulnerability

Remediation for The Remote Access Blind Spot

Patches

  • ConnectWise ScreenConnect 25.2.4+ (CVE-2025-3935) and 25.8+ (CVE-2025-14265)
  • N-able N-central Aug 2025 and subsequent security releases (CVE-2025-8875, CVE-2025-8876, CVE-2025-9316, CVE-2025-11366, CVE-2025-11367)
  • TeamViewer per security bulletins TV-2025-1001/1002/1004 (CVE-2025-0065, CVE-2025-36537, CVE-2025-41421)

Immediate actions

  • Inventory and allow-list approved RMM tools per endpoint; alert on any RMM binary not on the approved list, cross-referencing the community LOLRMM catalog of known-abused tools
  • Flag and investigate any endpoint running more than one RMM/remote-access tool simultaneously (Acronis TRU's own baseline: this is normal at 63% of SMB endpoints, so use deviation from the org's own approved set, not raw multiplicity, as the trigger)
  • Block outbound connections to known help-desk-scam RMM distribution domains (see IOCs) and enforce EDR execution blocking on unauthorized portable RMM installers
  • Patch N-able N-central, ConnectWise ScreenConnect, TeamViewer, and AnyDesk to current versions immediately to close CVE-2025-8875/8876/9316/11366/11367, CVE-2025-3935/14265, and CVE-2025-0065/36537

Workarounds

  • Restrict RMM console access to VPN/allow-listed source IPs where immediate patching is not possible
  • Disable unattended-access and auto-start-with-Windows features on RMM clients not actively required for IT operations

Longer-term hardening

  • Require MFA and conditional access on every RMM/remote-access console, and require verified callback procedures before help desks action remote-access or password-reset requests
  • Segment MSP/RMM management traffic onto its own network zone, separate from general user and production segments
  • Deploy behavioral EDR detections for RMM-specific silent-install command lines (e.g., AnyDesk.exe --install --start-with-win --set-password) rather than relying on domain/signature reputation alone
  • Treat RMM traffic as a monitored, not inherently trusted, channel; baseline expected RMM vendor/destination pairs per endpoint and alert on new ones

CVEs associated with The Remote Access Blind Spot

CVE-2025-8875, CVE-2025-8876, CVE-2025-9316, CVE-2025-11366, CVE-2025-11367, CVE-2025-3935, CVE-2025-14265, CVE-2025-0065, CVE-2025-36537, CVE-2024-1708, CVE-2024-1709

Weaknesses (CWE) in The Remote Access Blind Spot

CWE-502, CWE-20, CWE-77, CWE-269, CWE-287

Timeline of The Remote Access Blind Spot

  • CISA/NSA later document an October 2022 phishing campaign in which actors used help-desk-themed lures to deliver portable AnyDesk and ScreenConnect executables for bank-refund scams — the earliest widely-cited case of RMM software weaponized as first-stage malware.
  • CISA, NSA, and MS-ISAC publish Advisory AA23-025A, 'Protecting Against Malicious Use of RMM Software,' formalizing IOCs and mitigations for the RMM-abuse pattern.
  • ConnectWise discloses CVE-2024-1708 and CVE-2024-1709 (ScreenConnect authentication-bypass/path-traversal chain), rapidly weaponized by LockBit and Black Basta affiliates for mass exploitation.
  • A high-severity TeamViewer Windows client privilege-escalation flaw, CVE-2025-0065, is disclosed and patched (H-ISAC advisory).
  • LockBit 3.0 affiliates are reported exploiting a Confluence RCE for initial access, then deploying AnyDesk via Metasploit stagers and detonating ransomware within roughly two hours of compromise.
  • CISA adds ConnectWise ScreenConnect CVE-2025-3935 (ViewState code injection, actively exploited, suspected nation-state activity against a subset of customers) to the Known Exploited Vulnerabilities catalog.
  • N-able discloses CVE-2025-8875 (deserialization) and CVE-2025-8876 (improper input validation) in N-central, both CVSS 9.4 and exploited in the wild; over 1,000 unpatched internet-exposed instances identified.
  • Halcyon.ai TTP tracking marks its most recent confirmed sightings (November 2025) of LockBit and Akira affiliates using AnyDesk for post-compromise remote access.
  • Acronis TRU's full-year 2025 RMM vulnerability tally feeding this report closes out: TeamViewer 19 CVEs (2 critical), N-able 8, ConnectWise ScreenConnect +2, AnyDesk +2 — every one rated high or critical.
  • Acronis TRU publishes 'The remote access blind spot,' analyzing telemetry from 1.8M+ endpoints (Jan 2025-Mar 2026) and finding 63% run multiple RMM tools, over a third running three or more.

Sources cited for The Remote Access Blind Spot

More in threat intel

Detection coverage for TL-2026-2115

As of 2026-05-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2115 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats