palmiq Speak to an expert

RMM Security Best Practices to Stop Ransomware

6 min read Acronis

RMM security best practices for SMBs: how ransomware crews abuse remote-access tools, what CISA reported on SimpleHelp, and the controls that cut the risk.

System with various wires managing access to centralized resource of server in data center

Most ransomware advice for small businesses starts at the perimeter: filter the email, patch the firewall, train the staff. Useful, but incomplete. A growing share of incidents now arrives through the software that exists to manage your computers — remote monitoring and management (RMM) agents, remote-support clients, unattended-access tools. That is why RMM security best practices belong on the same priority tier as email security for an SMB in 2026.

The uncomfortable part: these tools are trusted by design. They are signed, allow-listed, and already running with administrative rights on every endpoint you own. An attacker who reaches one does not need to break anything. They just use it.

What is RMM tool abuse in a ransomware attack?

RMM tool abuse is when an attacker uses legitimate remote-management software — yours, your vendor’s, or a copy they installed themselves — to move through a network, stay resident, steal data, and deploy ransomware.

It shows up in two shapes:

Supply-chain exploitation. Someone compromises an unpatched RMM instance operated by a vendor or provider, then reaches that vendor’s downstream customers.

“Bring your own RMM.” The attacker installs their own copy of a legitimate remote-support tool on a victim machine. Traffic looks like routine IT activity, and security tooling sees a legitimate signed binary doing what it was built to do.

Darktrace research published as of January 2026 describes the Medusa ransomware operation leaning on RMM tools for persistence, lateral movement and data exfiltration rather than building custom remote-access trojans. Darktrace notes Medusa was among the ten most active ransomware actors in 2025, with more than 500 claimed victims. This is playbook behavior now, not a novelty.

What did CISA say about the SimpleHelp RMM ransomware attacks?

CISA issued advisory AA25-163A on June 12, 2025, in response to ransomware actors exploiting an unpatched vulnerability in SimpleHelp RMM to compromise the downstream customers of a utility billing software provider.

According to CISA, SimpleHelp versions 5.5.7 and earlier contain multiple vulnerabilities, and ransomware actors had been targeting organizations through unpatched SimpleHelp instances since January 2025. One of those flaws, CVE-2024-57727, was added to CISA’s Known Exploited Vulnerabilities catalog; public reporting attributes the campaign to the DragonForce ransomware operation.

Two caveats worth stating plainly. First, this involved unpatched instances — not a claim that the product is inherently unsafe. Second, that advisory dates from June 2025, and affected version ranges and remediation guidance get revised. Check the current CISA advisory and KEV entry rather than relying on any summary, including this one.

The part SMB owners should sit with: victims were reached through a software provider’s tooling, not through their own perimeter. CISA directed guidance specifically at third-party software vendors and MSPs that use RMM to manage customer networks, and recommended software bill of materials (SBOM) practices to reduce inherited supply-chain vulnerabilities. Regulators now treat the management layer itself as in-scope infrastructure.

Can hackers use remote access software to install ransomware?

Yes — and increasingly they prefer to. Acronis Threat Research Unit reported on March 6, 2026 that since March 2025 it has observed an increase in attacks using trojanized ConnectWise ScreenConnect installers to gain initial access to U.S.-based organizations, with attackers shifting to evasive ClickOnce runner installers and dropping multiple RATs onto a single machine.

The delivery routes are ordinary:

  • Cybersecurity News documented (October 14, 2025) phishing campaigns using fake IT alerts and remote-session invite links to trick users into granting ScreenConnect access.
  • Microsoft’s Security Blog documented (May 26, 2026) poisoned search results delivering a cryptojacking campaign that abuses ScreenConnect and Microsoft .NET utilities, noting the persistent remote access it establishes could later support data theft, lateral movement or ransomware.
  • Forcepoint X-Labs reported (February 12, 2026) that attacks against ScreenConnect have increased, with attackers abusing outdated or revoked RMM clients as a remote-access trojan to achieve persistent control while evading traditional detection.

More recently, IT Security Guru reported on September 3, 2026 that Huntress had observed a wave of malicious ScreenConnect installations spreading between machines with no further action from victim or attacker. Treat that one as early-stage incident reporting — it comes here via secondary coverage, and initial findings of this kind are frequently revised.

None of this means a properly maintained ScreenConnect or SimpleHelp deployment is a liability. It means the category is being targeted, and “we have antivirus” is not a response to a signed, legitimate binary.

How do I know if a remote-access tool was installed by an attacker?

Start with an inventory, because most owners have never seen one. Ask your IT provider for a list of every remote-control and remote-support agent installed across your fleet — product name, version, machine, and who authorized it.

Then reconcile it. Three questions do most of the work:

  1. Which of these tools do we actually use, and who approved each one?
  2. Is anything installed on only a handful of machines, or installed outside a normal deployment window?
  3. Does any agent connect to a management console that nobody in our business or our provider’s business controls?

Anything that cannot be accounted for is an incident until proven otherwise. Do not uninstall it first and investigate later — that destroys the evidence you need to understand scope.

How do I secure my RMM tool from ransomware?

The practical control set is unglamorous and mostly cheap:

  • Inventory and monitor. Maintain the list above, and alert on any new remote-control tool installation anywhere in the environment.
  • Block what you did not approve. Use application control to prevent unapproved RMM binaries from executing.
  • Patch RMM servers and agents on firewall urgency. Acronis’s H2 2025 Cyberthreats Report cites unpatched vulnerabilities as the initial access vector in 27% of the MSP-targeted cases it analyzed, second only to phishing at 52%.
  • Protect the consoles. MFA and conditional access on every remote-management console, plus IP or device restrictions where your tooling supports it.

Does MFA on remote access stop ransomware? No single control does. MFA on management consoles closes off credential reuse, which is one of the most common routes in — but it does nothing about an attacker-installed second RMM tool that never touches your console. That is why inventory and application control sit next to it on the list.

What should I ask my IT provider about remote access security?

Ask how they secure their own management plane. Acronis’s H2 2025 report describes roughly 150 MSP and telecom organizations directly targeted by ransomware in 2025 — the provider layer is a target in its own right.

Reasonable questions: How is access to your RMM console authenticated and restricted? How quickly do you patch the RMM platform itself? How are customer tenants separated? What would you tell us, and how fast, if your platform were compromised?

A provider that answers these specifically is a better sign than one that answers confidently.

What happens if the management plane falls?

Assume it can. If an attacker controls the RMM, they can reach the same endpoints your backup agent runs on — which is the argument for recovery points that are immutable, isolated from production credentials, and restored in a rehearsal before you need them for real.

Backup and EDR reduce impact and shorten recovery. They do not guarantee an outcome, and capabilities vary by product tier — including with Acronis, so confirm what your specific license actually includes before you build a plan around it.

Scale is the reason to do this now rather than next quarter. Acronis reported 3,642 publicly claimed ransomware victims between January and June 2025, up nearly 70% against the same period in both 2023 and 2024, and its H2 2025 report cites more than 7,600 publicly disclosed victims for the year, led by Qilin (962), Akira (726) and Cl0p (517). Verizon 2025 DBIR data cited by Acronis puts ransomware in 44% of confirmed breaches and 88% of breaches at small and medium businesses.

Your remote-access surface is a supply chain. Most SMBs have simply never been shown a map of it.

See how ransomware plays out against a real environment — and what recovery actually looks like: Protect your business from ransomware with Acronis.

Want this handled for you?

We run managed IT, security and backup for organizations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700