Remote monitoring tools are the backbone of how every managed IT firm operates – the software that lets a technician see your endpoints, push patches, and respond to alerts without leaving their desk. They are trusted, signed by major vendors, and whitelisted by most antivirus products wherever they run. That is exactly why threat actors have made remote monitoring tools a primary vehicle for persistent access inside small business networks. The 2024 and 2025 incident response data leaves no room for debate about how serious this has become.
- The Threat Landscape: Trusted Tools Turned Against You
- What 2024 – 2025 Incident Response Data Actually Says
- Who Gets Targeted: Why Small Businesses Are Prime Targets
- Real-World Examples and Advisory Disclosures
- How the Attack Actually Works: From Intrusion to Invisible Persistence
- A Defensible Posture: What Good Looks Like
- What to Ask Your IT Firm
- Why Monitoring the Monitors Has Never Mattered More
The Threat Landscape: Trusted Remote Monitoring Tools Turned Against You
Security researchers call it “living off the land.” The concept is simple: instead of introducing foreign malware that might trigger detection, an attacker uses software already trusted inside the target environment. They blend in. They look like normal IT operations. They persist for months.
Remote monitoring tools are now the preferred living-off-the-land vehicle in small and mid-sized business environments. Products like AnyDesk, TeamViewer, ScreenConnect (ConnectWise), and Atera are legitimate, widely deployed, and designed to provide full remote control of a machine. When an attacker installs one of these tools after gaining an initial foothold, the connection it creates looks indistinguishable from routine IT maintenance traffic to most security tools.
CISA has been direct about this. In January 2024, CISA and the NSA released joint guidance warning that threat actors are using legitimate remote monitoring and management software to maintain persistence, move laterally, and avoid detection inside compromised environments. That advisory did not describe a theoretical future risk. It described an active, documented pattern already playing out across thousands of organizations.
What 2024 – 2025 Incident Response Data Actually Says

The FBI’s Internet Crime Complaint Center 2023 report, released in 2024, recorded over $12.5 billion in reported cybercrime losses in the United States – the highest figure the agency has ever published. Business email compromise and ransomware remain the leading loss categories, but the delivery mechanism underneath many of these attacks has shifted decisively toward legitimate tooling.
Mandiant’s 2024 M-Trends report found that median attacker dwell time – the gap between initial intrusion and detection – held at around ten days across all incident types. In cases involving legitimate remote access tooling, those dwell times extended dramatically. Attackers who established persistence through a trusted remote monitoring agent stayed inside environments for weeks or months before any anomalous behavior triggered a response.
CrowdStrike’s 2025 Global Threat Report reinforced the picture. Identity-based and tool-abuse intrusions now account for a majority of observed incident patterns, with threat actors actively avoiding custom malware in favor of tools that blend with normal operations. Remote administration tools were specifically called out as a top persistence mechanism.
Sophos, which publishes detailed incident response data from real small business engagements, has documented repeated cases where attackers installed a secondary remote monitoring agent – separate from the one the victim’s IT firm was using – and maintained access through it for months. Because the tool itself was legitimate, endpoint protection products largely ignored it.
Who Gets Targeted: Why Small Businesses Are Prime Targets
Larger organizations with dedicated security teams run behavioral analytics that can flag the installation of a new remote monitoring agent at an unusual hour, or an outbound persistent connection to an unfamiliar server. Small businesses typically do not have that layer of oversight.
A 25-person professional services firm almost certainly relies on its IT firm’s tooling and a basic endpoint protection product – nothing more. There is no behavioral baseline monitoring. There is no network traffic analysis watching for unexpected persistent connections. When an attacker installs a legitimate remote monitoring tool on one of those endpoints, nothing fires an alert, because nothing is configured to look for it.
Small businesses are also attractive because of where they sit in supply chains. A law firm managing documents for a mid-market manufacturer, a healthcare consulting firm holding patient data on behalf of hospital clients, a pharmaceutical consulting firm subject to client security questionnaires – these organizations are targets not just for their own data but for the upstream access they represent. Attackers understand that the perimeter of a large enterprise often has a small business somewhere along its edge.
The Verizon 2024 Data Breach Investigations Report found that small businesses experienced breaches at roughly the same rate as larger organizations. They simply had far less capacity to detect or respond before significant damage occurred.
Real-World Examples and Advisory Disclosures
CISA advisory AA24-016A, co-authored with the NSA and MS-ISAC in January 2024, documented a specific threat actor pattern running since at least mid-2022. The threat actors compromised network environments and deployed commercial remote monitoring tools – including ScreenConnect and AnyDesk – to maintain persistent footholds. These were not cracked or modified versions. They were fully licensed, fully functional installations, making them nearly invisible to signature-based detection.
The advisory described attackers using phishing emails impersonating IT helpdesk communications to convince employees to install remote monitoring software directly. No exploit was needed. The user clicked a link, authenticated a session, and the attacker had persistent access – while the target believed they were receiving legitimate IT support.
In a separate disclosure, CISA’s Known Exploited Vulnerabilities catalog added critical ConnectWise ScreenConnect flaws in February 2024 (CVE-2024-1708 and CVE-2024-1709) – authentication bypass vulnerabilities being actively exploited in the wild. Attackers who could reach an on-premises ScreenConnect server could bypass authentication entirely and deploy remote agents at will. ConnectWise patched quickly, but organizations running unpatched installations remained exposed, and incident response firms documented active exploitation within days of public disclosure.
The Microsoft Threat Intelligence team published 2024 research documenting how ransomware groups – including those operating under the Black Basta and Scattered Spider banners – were using legitimate remote monitoring and management tools as a post-compromise persistence layer before deploying their encryptors. The tools provided stable, reliable access to conduct reconnaissance, locate backup infrastructure, and disable protections before triggering the final payload.
How the Attack Actually Works: From Intrusion to Invisible Persistence
Understanding the attack sequence is essential for appreciating why conventional defenses miss it. The pattern typically unfolds in five stages.
Stage one: Initial access. The attacker gains a foothold through a phishing email, a credential obtained from a prior breach, or exploitation of an internet-facing system. This is the noisiest part of the attack – and it is often over before any alert fires.
Stage two: Tool deployment. Rather than deploying a custom backdoor that might be flagged, the attacker downloads and installs a legitimate remote monitoring agent, configured to connect back to an attacker-controlled server registered with the tool’s legitimate infrastructure. The installation looks identical to a normal IT management deployment.
Stage three: Persistence through legitimacy. The remote monitoring tool establishes an outbound persistent connection to the attacker’s relay infrastructure. Because the traffic is encrypted, signed by a legitimate certificate authority, and originates from a trusted executable, it passes through most network monitoring and endpoint protections without any alert. The attacker now has reliable, durable access they can return to at will.
Stage four: Quiet reconnaissance and lateral movement. Over days or weeks, the attacker maps the environment using the same visibility your IT firm has. They identify backup systems, financial accounts, email archives, and credentials. They may install additional remote monitoring agents on other endpoints to hedge against losing their initial foothold.
Stage five: The payload or the exit. Depending on their objectives, they deploy ransomware, exfiltrate data quietly, or sell the persistent access to another threat actor. By this stage, they may have been inside the environment for sixty, ninety, or even a hundred and twenty days.
A Defensible Posture: What Good Looks Like
Defending against this attack pattern requires accepting one uncomfortable truth: signature-based detection alone will not stop it. If the remote monitoring tool is legitimate, it has no malware signature. Defense has to operate at the behavioral and configuration level.
Several controls make a meaningful difference:
- Application allowlisting for remote monitoring tools. Only the specific remote monitoring agent your IT firm uses – running under its expected process name and connecting to its known infrastructure – should be permitted. Any other installation of that tool type should generate an immediate alert.
- Network traffic monitoring with behavioral baselines. Even when traffic is encrypted, the destination, frequency, and timing of outbound persistent connections can surface anomalies. A new persistent connection to an unfamiliar infrastructure provider established at 2 AM warrants investigation regardless of whether the traffic itself can be inspected.
- Phishing-resistant multi-factor authentication everywhere. The most common initial access vector for these attacks is credential-based. Authenticator-app or hardware-key multi-factor authentication eliminates a large share of credential-based intrusion attempts.
- Privileged access management. Restricting which accounts can install software – and which can create outbound connections on non-standard ports – limits an attacker’s ability to deploy new tooling even after gaining an initial foothold.
- Patch management enforced against IT management software itself. The ConnectWise ScreenConnect vulnerabilities from early 2024 were being actively exploited within days of public disclosure. Organizations that patched within 24 to 48 hours were largely protected. Those on weekly or monthly patch cycles were not.
- Tabletop exercises that model IT tool abuse. Most small business incident response plans treat malware as the assumed threat. Running a scenario where the “attacker” is a legitimate remote monitoring agent forces the team to find detection gaps they would otherwise miss.
The CISA free cybersecurity resources library includes detection guidance and tooling recommendations specifically aimed at organizations without large security teams. It is worth reviewing for any small business that wants to understand its baseline posture.
For organizations wanting to understand how these controls fit inside a broader security program, Xact IT’s cybersecurity services page describes the layered approach we apply for managed clients – built around documented frameworks, not individual point products.
What to Ask Your IT Firm
Here is the most important insight this threat pattern produces for any business owner or executive: your IT firm’s own software can be turned against you, and most IT firms are not specifically monitoring for that scenario. The questions you ask your current provider should reflect that reality.
- What remote monitoring tools do you run in our environment, and how would you detect if an unauthorized second instance of that type of tool were installed? A vague answer is a meaningful gap.
- Do you maintain a documented baseline of every persistent outbound connection in our environment, and do you review that baseline for anomalies? A firm that does not know what “normal” looks like cannot identify what is not.
- How quickly did you patch the ConnectWise ScreenConnect vulnerabilities (CVE-2024-1708 and CVE-2024-1709) disclosed in February 2024? The speed and specificity of the answer reveals how the firm handles critical patch windows.
- How do you separate your administrative access to our environment from the access a compromised credential at your firm would provide? If an attacker compromises your IT firm’s management account, what stops them from reaching your systems?
- Have you run any scenario planning specifically modeling an attack that uses legitimate IT tooling as the persistence mechanism? This tests whether the firm thinks offensively about its own toolset.
- What logging do you maintain from the remote monitoring agents in our environment, and how long is that data retained? Without adequate log retention, forensic investigation after an incident becomes nearly impossible.
These are not adversarial questions. A firm with a mature security posture will welcome them and answer them specifically. A firm that becomes defensive or offers generic reassurances is telling you something important about how carefully they have thought through their own attack surface.
Why Monitoring the Monitors Has Never Mattered More
The 2024 and 2025 incident response data makes one thing clear: remote monitoring tools – the very software designed to keep small businesses running – have become one of the most reliable weapons in the modern attacker’s toolkit. Every organization that relies on a managed IT provider is, by definition, running remote monitoring software in its environment. That is not a reason to abandon these tools. It is a reason to treat them with the same scrutiny you would apply to any powerful, privileged system.
Monitoring the monitors means establishing a documented baseline of which remote monitoring agents are authorized to run, where they connect, and what behavior is normal. It means ensuring your IT firm has logging in place that would surface an unauthorized agent if one appeared. It means treating critical vulnerabilities in IT management software with the same urgency you would give a firewall zero-day – because the exposure is comparable.
Small businesses that approach this proactively are not just defending against one specific attack type. They are building the detection and response capability that makes every category of threat harder to execute. An attacker who cannot establish durable persistence has a fundamentally shorter window to cause harm. Controlling which remote monitoring tools are permitted, monitoring outbound connections for anomalies, and working with an IT firm that has thought carefully about its own attack surface – these are among the highest-leverage investments a small business can make in its security posture right now.
If your current IT provider cannot answer the questions in the previous section with specificity and confidence, that conversation itself is valuable information. See what a security-first managed IT engagement looks like on our managed IT services page – or Book a Free Cybersecurity Strategy Call to talk through your environment directly.
Want a Walkthrough of Your Own Setup?
Twenty minutes on the phone with our team gets you specific recommendations you can use immediately — whether you hire us or not. No pitch, no pressure, just an honest read on where your business stands.