Skip to content
Bomgar RMM Exploitation Fuels LockBit Attacks

Bomgar RMM Exploitation Fuels LockBit Attacks

Socprime April 22, 2026

Huntress reported a rise in attacks abusing compromised Bomgar remote monitoring and management instances following public disclosure of CVE-2026-1731. Threat actors used the flaw to execute code remotely, create high-privilege accounts, and deploy additional remote access software and ransomware. In several cases, the activity led to the deployment of LockBit ransomware, along with tools such as AnyDesk and Atera. The campaign affected both direct Bomgar customers and the downstream organizations they support.

The Huntress SOC tracked multiple incidents between February and April 2026 and identified malicious activity tied to bomgar-scc.exe , with attackers using hijacked RMM sessions to launch tools including NetScan, HRSword, and custom drivers. The intruders created new local and domain administrator accounts, installed secondary RMM agents, and executed the LockBit ransomware payload LB3.exe . Investigators also found signs of leaked LockBit 3.0 builder usage and bring-your-own-vulnerable-driver techniques within affected environments.

Organizations should apply the official BeyondTrust Remote Support patches that address CVE-2026-1731 and upgrade affected systems to version 25.3.2 or later. Security teams should also monitor for unexpected privileged account creation, execution of unauthorized RMM tools, suspicious scheduled tasks, and unusual driver installations. Strong access controls and tighter oversight of RMM platforms are essential to reduce the risk of similar compromise.

If this activity is detected, isolate the impacted systems immediately, revoke any compromised Bomgar credentials, and remove unauthorized remote management tools from the environment. Incident responders should then perform forensic analysis to identify ransomware payloads, persistence mechanisms, and any lateral movement. Recovery efforts should rely on clean backups, while downstream customers should be notified promptly so coordinated remediation and hardening can begin.

Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.

Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic.

Attack Narrative & Commands:

The exact command line executed on the compromised host is:

A similar command is run for the domain group:

Regression Test Script:

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.