Rogue RMM abuse: control who can remotely access your business
26 September 2026
Reduce rogue RMM abuse with approved support tools, verified support requests and installation alerts. Practical checks for Australian SMBs.
Huntress reports that its security operations centre uncovered phishing attacks that persuaded employees to install remote monitoring and management (RMM) software for attackers. For Australian SMBs, rogue RMM abuse creates a practical problem: software used for legitimate IT support can also give an intruder ongoing access.
In its report on phishing and persistent remote access, Huntress identifies misuse of tools including ScreenConnect. The issue is not that a recognised product is inherently malicious. It is whether the installation, its operator and its connection to your business are authorised.
Why rogue RMM abuse is different from ordinary malware
Remote support tools let technicians view screens, transfer files and administer devices, depending on their permissions and configuration. Those same capabilities are useful to attackers who convince someone to run an installer or join a support session.
A valid software signature does not prove that the person requesting access works for your provider. An installation can be genuine software connected to an attacker-controlled account.
Some tools also support unattended access. Closing a support window may not remove the installed component or prevent a later connection. Defending against rogue RMM abuse therefore requires more than telling staff to avoid suspicious attachments: the business must define which remote access is permitted and detect deviations.
Build an approved remote support tool register
Start by asking your internal IT team and managed service provider to identify every remote access tool they use. Include specialist suppliers supporting accounting systems, equipment and line-of-business applications.
Create a register that records:
- Product and business purpose: why the tool is needed and which systems it supports.
- Accountable owner: who approves its use and reviews access.
- Approved operator: the internal team or external provider allowed to connect.
- Management environment: the expected tenant, server or connection destination, where identifiable.
- Permitted devices: the endpoints or device groups covered by the approval.
- Access mode: attended support only, or explicitly approved unattended access.
- Review and removal conditions: when access expires and who removes it.
Do not approve a product name alone. Rogue RMM abuse can involve the same product your provider already uses, but enrolled into a different management environment.
Compare the register with actual device inventory. Investigate tools left by former providers, duplicate agents and installations without an owner. Arrange removal through a controlled change rather than deleting something that may support a critical system.
Give staff a simple support verification procedure
An unexpected call or message about an urgent computer problem should trigger verification, not an installation. Staff need a clear process that still works when the request sounds plausible.
Use these steps:
- Pause the request. Do not open the supplied link, run software or disclose passwords or authentication codes.
- Contact support independently. Use a saved service desk number, an established support portal or your internal directory, not details supplied in the unexpected message.
- Confirm the work. Check the ticket, technician identity, affected device and reason for remote access.
- Follow the approved connection process. If a different tool is requested, obtain approval from the designated IT owner first.
- Report uncertainty promptly. Staff should know how to report a request even if they already clicked or started a session.
A caller knowing an employee's name or provider's brand is not sufficient verification. Neither is a professional-looking download page.
Make the procedure available outside the affected computer, such as through a staff contact card. If email or the device is compromised, employees still need a trusted route to support.
Alert on installations and unexpected remote access
Software inventory is useful, but a periodic spreadsheet review may identify an unauthorised tool too late. Ask your IT provider what triggers an alert and who receives it.
Useful monitoring checks include:
- A remote support application appearing on a device outside its approved group.
- A new background service or startup entry associated with remote access software.
- An approved product connecting to an unfamiliar management destination.
- A remote support executable running from a download or temporary folder.
- Changes to unattended access settings or unexpected administrative access.
Where telemetry allows, correlate these signals with the user, device, download source and any support ticket. A recognised product running during an approved session is different from an unexplained installation following an email link.
Installation alerts alone are not enough. Some remote access tools run without a conventional installation, and some work within a standard user's permissions. Combine inventory, endpoint monitoring and application controls where supported.
For each alert, nominate an owner, a response timeframe and an escalation path. Agree in advance who can authorise device isolation. An alert nobody reviews does little to contain rogue RMM abuse.
Restrict access without breaking legitimate support
Remove unnecessary local administrator rights, but do not treat this as a complete defence. It can restrict some installations without stopping every remote session.
Use application control to limit unapproved software where practical. Test rules on representative devices first, including systems supported by specialist vendors. Broad rules that trust every signed application may still permit unwanted remote access.
For approved support platforms, check:
- Technicians use individual accounts rather than shared credentials.
- Multi-factor authentication is enabled where available.
- Permissions are limited to the customers, devices and functions each operator needs.
- Session logging is enabled and retained according to business requirements.
- Departing staff and former suppliers lose access promptly.
- Unattended access is restricted to an explicit operational need.
Keep approved tools patched as well. Authorisation checks and vulnerability management address different risks; neither replaces the other. Our exploited-vulnerability review checklist explains the separate checks needed when software vulnerabilities are actively exploited.
Respond carefully if someone has already granted access
Treat an unexplained remote session as a potential security incident, even if the employee only saw routine support activity.
Contact your incident response lead or IT provider through a trusted channel. Follow the agreed containment process, which may include isolating the device through endpoint tooling or disconnecting its network connection. Coordinate carefully where isolation could interrupt critical operations.
Preserve the message, phone number, download address, approximate times and any ticket details. Avoid wiping the device or simply uninstalling the tool before responders assess what evidence is needed.
The investigation should establish whether unattended access remains, what accounts were used and whether files, credentials or other systems were accessed. Where credential exposure is suspected, responders should assess session revocation and credential changes from a trusted device.
If personal information may have been accessed, assess applicable notification obligations with appropriate advice. A suspicious installation does not automatically establish a notifiable breach.
Turn the checks into routine operations
Within the next month, assign an owner to the approved tool register, reconcile it against device inventory and test one unexpected-support scenario with staff. Ask your provider to demonstrate how an unauthorised remote tool would be detected and escalated.
Include these controls in your broader cyber threat readiness checklist. Review them when suppliers, support tools or business systems change.
To reduce exposure to rogue RMM abuse, review your cyber security with Tech Engine Australia. Call 1300 088 324 or email sales@techengine.au to discuss remote access controls, endpoint monitoring and incident response responsibilities.
Want this applied to your business?
Request an AI Blueprint and we will map the processes worth automating first.
Request an AI Blueprint