The Microsoft Threat Intelligence Podcast 9.9.26
Ep 77 | 9.9.26

Why Threat Actors Love Your RMM

Show Notes

In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Grant, Principal Threat Intelligence Incident Commander at Huntress. 

They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft. 

In this episode you’ll learn:      

  • How AI is making phishing lures and fake websites more convincing 
  • Why trusted remote-access software can evade traditional endpoint detection 
  • How security teams can identify and block unauthorized RMM activity 

Some questions we ask:     

  • What information are attackers looking for once they gain access? 
  • Why are attackers choosing legitimate tools instead of traditional malware? 
  • How does compromised access eventually lead to ransomware or data theft? 

Resources:  

Huntress report on RMM abuse 

View Andrew Grant on LinkedIn  

View Elliot Volkman on LinkedIn  

 Related Microsoft Podcasts:                   

 

Discover and follow other Microsoft podcasts at⁠ ⁠⁠microsoft.com/podcasts  

 

Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

 

The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.