A Playbook for Hardening Remote Access Tools in SMBs

· Original article ↗

Summary

Acronis outlines ways SMBs and MSPs can reduce risk from abused remote access tools, including RDP, ScreenConnect, MeshAgent and VNC, with guidance on hardening, monitoring and controlling installations.

Key points

  • Acronis says 63% of endpoints in its earlier telemetry had more than one remote access tool, potentially increasing attack surface.
  • Attackers enable RDP, disable protections, use RDPWrap for hidden concurrent sessions, and extract saved credentials; recommendations include disabling unnecessary RDP and requiring VPN or ZTNA access.
  • ScreenConnect has been targeted through CVE-2024-1709 and trojanized installers; Acronis reports some attacks used ClickOnce runners to download components and deploy RATs.
  • MeshAgent can install as a persistent Windows service; Acronis recommends blocking it where unauthorized and investigating failed automated removal.
  • Acronis classified 95.8% of VNC-related EDR incidents in its dataset as malicious; observed activity included hidden VNC servers and credential theft.
  • The playbook recommends blocking tools commonly seen in attack contexts, monitoring and hardening dual-use tools, and auditing mainstream tools for authorized installations.
  • Core controls include reducing tool sprawl, patching internet-facing RMM servers, enforcing MFA, inventorying authorized agents, and investigating tools connecting to unknown servers.

Article Details

Topic
Hardening remote access and RMM deployments against attacker abuse in SMB and MSP environments

MITRE ATT&CK

CVE

Threat Actors

Malware

Vendors

Products

Acronis Cyber Protect Cloudmultiple remote access tools, and many of those extra installations may be redundant. With Acronis Cyber Protect Cloud, you can monitor and investigate installed software on endpoints using “Software Inventory.”Action1of unauthorized instances or exploitation of vulnerabilities: VNC/UltraVNC, RDP, Tactical RMM, and Action1. For these, enforce strict deployment policies, patch quickly, require MFA, and investigate any instanceAmmyy AdminAdditionally, we’ve found that tools like MeshAgent and Ammyy Admin showed up in EDR incidents far more often than in legitimate IT deployments, demonstrating how some tools are far more likely to be used as part of anAnyDeskWidely trusted tools like ConnectWise ScreenConnect and AnyDesk may be abused by attackers, and when left unattended, they can present a problem: Their legitimate prevalence makes attacker activity harder to spot, andConnectWise ScreenConnectWidely trusted tools like ConnectWise ScreenConnect and AnyDesk may be abused by attackers, and when left unattended, they can present a problem: Their legitimate prevalence makes attacker activity harder to spot, andMeshAgentAdditionally, we’ve found that tools like MeshAgent and Ammyy Admin showed up in EDR incidents far more often than in legitimate IT deployments, demonstrating how some tools are far more likely to be used as part of anMeshCentralMeshAgent is the open-source agent component of MeshCentral. Across our dataset, it is the single most frequently deployed tool by attackers, appearing in hundreds of incidents.Splashtopwith low malicious-to-legitimate ratios include ConnectWise ScreenConnect, AnyDesk, TeamViewer, and Splashtop. These tools still require hardening: patching, MFA, authorized-instance tracking, and regular audits ofTactical RMMthrough deployment of unauthorized instances or exploitation of vulnerabilities: VNC/UltraVNC, RDP, Tactical RMM, and Action1. For these, enforce strict deployment policies, patch quickly, require MFA, andTeamViewerremote access tools with low malicious-to-legitimate ratios include ConnectWise ScreenConnect, AnyDesk, TeamViewer, and Splashtop. These tools still require hardening: patching, MFA, authorized-instance tracking, andUltraVNCOf the hundreds of EDR incidents involving VNC variants, primarily UltraVNC, 95.8% were classified as malicious. EDR incidents are categorized as suspicious, rather than malicious, when a tool is flagged mainly for

Tools

Related Articles