Skip to content
Surge in Phishing Attacks Using RMM Tools Targeting Financial Institutions

Surge in Phishing Attacks Using RMM Tools Targeting Financial Institutions

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 18:40 UTC
  • •Phishing attacks using RMM tools surged by 475% in 2026.
  • •Attackers exploit legitimate software like AnyDesk to gain persistent access.
  • •Financial institutions are the primary targets of these phishing campaigns.

Cybercriminals have significantly increased the use of legitimate remote monitoring and management (RMM) tools, such as AnyDesk, in phishing attacks, with a reported 475% rise in such campaigns during the first nine months of 2026 compared to all of 2025. These attacks primarily target North American financial institutions and commercial banking customers. Attackers trick victims into installing RMM software via phishing emails, allowing them to gain persistent access to victim devices. Once inside, they can monitor user activity, steal credentials, and deploy additional malware. The Cybersecurity and Infrastructure Security Agency (CISA) previously issued advisories regarding the malicious use of RMM software, highlighting its potential for exploitation by both cybercriminals and advanced persistent threat (APT) actors. Organizations are advised to treat unauthorized RMM tools as security risks and maintain strict control over approved software lists. Balancing remote administration needs with security concerns remains a challenge for IT departments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-01
Surge in RMM tool phishing attacks observed
Phishing campaigns incorporating RMM tools increased by 475% compared to 2025, primarily targeting financial institutions.
Petri
2026-10-08
CISA issues advisory on RMM software exploitation
CISA warns of the malicious use of RMM software in phishing attacks, highlighting risks to network defenders.
www.cisa.gov

More articles in this cluster (2)

Common questions

What RMM tools are being exploited?
Cybercriminals are using legitimate RMM tools like AnyDesk and ScreenConnect to facilitate their attacks.
Who is primarily affected by these attacks?
The primary targets of these phishing campaigns are North American financial institutions and their customers.
What should organizations do to protect themselves?
Organizations should maintain an approved list of RMM tools, block unauthorized installations, and educate employees on phishing tactics.