We've seen an uptick in breaches starting with a little-known RMM called Tiflux. One moment, you’re opening an email with an attachment. The next, this RMM appears on your machine…along with a lot more. One of the earliest examples we saw started with a service agreement phish. Once attackers gain initial access via Tiflux, we’ve seen them install additional RMM tools and even outdated drivers to elevate their access. This gave them persistence, allowed them to transmit screenshots, and let them run commands to collect system profiling information. One innocuous remote tool gave attackers full access. But this barely scratches the surface of what RMM abuse can be used for. It was the #1 threat in our latest Cyber Threat Report for a reason, jumping 277% in the last year. On August 18, we're breaking down why RMMs are still such a problem, and what it actually takes to close the gap beyond visibility alone. Save your spot: https://okt.to/ZpJnoQ
One innocuous remote tool gave attackers full access. That is the pattern. The RMM is not the attack. It is the infrastructure the attack runs on. The AI agent version is already operational. An agent with RMM tool access does not need a human to execute lateral movement. It reasons its way through the environment autonomously. SPECTER AGENTRAT runs on-device SLMs with no continuous C2 required. The RMM is the entry point. The agent is the campaign. 277% jump in RMM abuse is the human-speed version of this problem. The autonomous version compounds it. AI Shield M19 v2.0 monitors agent runtime behaviour continuously. M101 AI Shield Identity covers NHI credential abuse across the tool access layer. When an agent starts using RMM access outside its established behavioural baseline, M19 flags it before the campaign completes. Red Specter Security Research
Ce cas illustre un angle mort récurrent : Tiflux est choisi par l'attaquant précisément parce qu'il est peu connu. Dans de nombreux environnements, un RMM non répertorié peut tourner des jours sans déclencher d'alerte, simplement parce qu'il ne figure pas dans les listes de surveillance IT. Chez Sorvek Security, on observe cette dynamique régulièrement : les outils d'accès à distance non inventoriés — qu'ils aient été déposés par un attaquant ou installés par un utilisateur sans autorisation — représentent l'un des angles morts les plus critiques. La détection commence par savoir ce qui est présent dans l'environnement, pas uniquement ce qui est déjà identifié comme malveillant.