Petri Surge in Phishing Attacks Using RMM Tools Targeting Financial Institutions
Article Content
- •Phishing attacks using RMM tools surged by 475% in 2026.
- •Attackers exploit legitimate software like AnyDesk to gain persistent access.
- •Financial institutions are the primary targets of these phishing campaigns.
Cybercriminals have significantly increased the use of legitimate remote monitoring and management (RMM) tools, such as AnyDesk, in phishing attacks, with a reported 475% rise in such campaigns during the first nine months of 2026 compared to all of 2025. These attacks primarily target North American financial institutions and commercial banking customers. Attackers trick victims into installing RMM software via phishing emails, allowing them to gain persistent access to victim devices. Once inside, they can monitor user activity, steal credentials, and deploy additional malware. The Cybersecurity and Infrastructure Security Agency (CISA) previously issued advisories regarding the malicious use of RMM software, highlighting its potential for exploitation by both cybercriminals and advanced persistent threat (APT) actors. Organizations are advised to treat unauthorized RMM tools as security risks and maintain strict control over approved software lists. Balancing remote administration needs with security concerns remains a challenge for IT departments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What RMM tools are being exploited?
Who is primarily affected by these attacks?
What should organizations do to protect themselves?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…