A Playbook for Hardening Remote Access Tools in SMBs

Summary
Acronis outlines ways SMBs and MSPs can reduce risk from abused remote access tools, including RDP, ScreenConnect, MeshAgent and VNC, with guidance on hardening, monitoring and controlling installations.
Key points
- Acronis says 63% of endpoints in its earlier telemetry had more than one remote access tool, potentially increasing attack surface.
- Attackers enable RDP, disable protections, use RDPWrap for hidden concurrent sessions, and extract saved credentials; recommendations include disabling unnecessary RDP and requiring VPN or ZTNA access.
- ScreenConnect has been targeted through CVE-2024-1709 and trojanized installers; Acronis reports some attacks used ClickOnce runners to download components and deploy RATs.
- MeshAgent can install as a persistent Windows service; Acronis recommends blocking it where unauthorized and investigating failed automated removal.
- Acronis classified 95.8% of VNC-related EDR incidents in its dataset as malicious; observed activity included hidden VNC servers and credential theft.
- The playbook recommends blocking tools commonly seen in attack contexts, monitoring and hardening dual-use tools, and auditing mainstream tools for authorized installations.
- Core controls include reducing tool sprawl, patching internet-facing RMM servers, enforcing MFA, inventorying authorized agents, and investigating tools connecting to unknown servers.
Article Details
- Topic
- Hardening remote access and RMM deployments against attacker abuse in SMB and MSP environments
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolAttackers use RDP for remote access after enabling it on compromised machines.T1021.005 · VNCAttackers deploy hidden VNC servers for remote access.T1036.005 · Match Legitimate Resource Name or LocationThe article identifies renamed LogMeIn binaries as masquerading.T1059.001 · PowerShellThe article describes deployment of a custom PowerShell RAT through ScreenConnect.T1105 · Ingress Tool TransferMeshAgent and Tactical RMM are described as being downloaded after compromise.T1112 · Modify RegistryAttackers modify Windows registry settings to enable RDP and disable Network Level Authentication.T1136.001 · Local AccountAttackers create local administrator accounts before enabling RDP.T1190 · Exploit Public-Facing ApplicationAttackers exploited the public-facing ScreenConnect authentication bypass CVE-2024-1709.T1219 · Remote Access ToolsAttackers deploy or abuse remote access software, including ScreenConnect, MeshAgent and VNC variants.T1543.003 · Windows ServiceAttackers install MeshAgent as a Windows service for persistence.T1546.008 · Accessibility FeaturesAttackers alter accessibility feature binaries for sticky-key-style backdoor access.
CVE
CVE-2024-12356ConnectWise ScreenConnect (CVE-2024-1709), BeyondTrust (CVE-2024-12356, CVSS 9.8), and SimpleHelp (CVE-2024-57727) were all exploited quickly after disclosure. Internet-facing RMM servers are high-value targets. WithCVE-2024-1709One such vector is vulnerability exploitation. CVE-2024-1709, for example, provided a trivially exploitable authentication bypass (CVSS 10.0) that allowed attackers to create admin accounts on unpatched servers. WithCVE-2024-57727ConnectWise ScreenConnect (CVE-2024-1709), BeyondTrust (CVE-2024-12356, CVSS 9.8), and SimpleHelp (CVE-2024-57727) were all exploited quickly after disclosure. Internet-facing RMM servers are high-value targets. With
Threat Actors
Malware
AsyncRATattackers leverage ScreenConnect's built-in automation to deploy malware within minutes, typically AsyncRAT, a custom PowerShell RAT and PureHVNC RAT simultaneously. The dual-RAT approach provides redundancy andPureHVNC RATbuilt-in automation to deploy malware within minutes, typically AsyncRAT, a custom PowerShell RAT and PureHVNC RAT simultaneously. The dual-RAT approach provides redundancy and may indicate shared infrastructure
Vendors
AcronisIn part one of this series, we analyzed Acronis telemetry from over 1.8 million managed endpoints to map the RMM tool risk facing SMBs and MSPs. The data showed that 63% of endpoints run more than one remote access toolConnectWiseWidely trusted tools like ConnectWise ScreenConnect and AnyDesk may be abused by attackers, and when left unattended, they can present a problem: Their legitimate prevalence makes attacker activity harder to spot, and
Products
Acronis Cyber Protect Cloudmultiple remote access tools, and many of those extra installations may be redundant. With Acronis Cyber Protect Cloud, you can monitor and investigate installed software on endpoints using “Software Inventory.”Action1of unauthorized instances or exploitation of vulnerabilities: VNC/UltraVNC, RDP, Tactical RMM, and Action1. For these, enforce strict deployment policies, patch quickly, require MFA, and investigate any instanceAmmyy AdminAdditionally, we’ve found that tools like MeshAgent and Ammyy Admin showed up in EDR incidents far more often than in legitimate IT deployments, demonstrating how some tools are far more likely to be used as part of anAnyDeskWidely trusted tools like ConnectWise ScreenConnect and AnyDesk may be abused by attackers, and when left unattended, they can present a problem: Their legitimate prevalence makes attacker activity harder to spot, andConnectWise ScreenConnectWidely trusted tools like ConnectWise ScreenConnect and AnyDesk may be abused by attackers, and when left unattended, they can present a problem: Their legitimate prevalence makes attacker activity harder to spot, andMeshAgentAdditionally, we’ve found that tools like MeshAgent and Ammyy Admin showed up in EDR incidents far more often than in legitimate IT deployments, demonstrating how some tools are far more likely to be used as part of anMeshCentralMeshAgent is the open-source agent component of MeshCentral. Across our dataset, it is the single most frequently deployed tool by attackers, appearing in hundreds of incidents.Splashtopwith low malicious-to-legitimate ratios include ConnectWise ScreenConnect, AnyDesk, TeamViewer, and Splashtop. These tools still require hardening: patching, MFA, authorized-instance tracking, and regular audits ofTactical RMMthrough deployment of unauthorized instances or exploitation of vulnerabilities: VNC/UltraVNC, RDP, Tactical RMM, and Action1. For these, enforce strict deployment policies, patch quickly, require MFA, andTeamViewerremote access tools with low malicious-to-legitimate ratios include ConnectWise ScreenConnect, AnyDesk, TeamViewer, and Splashtop. These tools still require hardening: patching, MFA, authorized-instance tracking, andUltraVNCOf the hundreds of EDR incidents involving VNC variants, primarily UltraVNC, 95.8% were classified as malicious. EDR incidents are categorized as suspicious, rather than malicious, when a tool is flagged mainly for