WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships LockBit Ransomware Gang Increasingly Targeting RMM Software to Establish Network Presence
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

LockBit Ransomware Gang Increasingly Targeting RMM Software to Establish Network Presence

Author: April Zupan

Created: Thursday, September 21, 2023 - 17:33

Categories: Cybersecurity, Federal & State Resources, Intelligence

Dark Reading has written an article discussing LockBit ransomware group and a recently observed evolution of its tactics to include the use of remote monitoring and management (RMM) software to expand its presence once on a victim’s network.

LockBit, which has been one of the most prolific ransomware actors in 2023, has been observed targeting and controlling RMM software once it establishes a network foothold. Both AnyDesk and ConnectWise have been observed being targeted, with LockBit going so far as to install a second instance of ConnectWise on a victim’s network when it was unable to steal their credentials. The article discusses a few mitigations against this tactic, including applying multi-factor authentication to their RMM software and establishing stricter access controls. Members are also encouraged to review CISA’s recently published Remote Monitoring and Management (RMM) Cyber Defense Plan, which is a valuable resource for organizations determining where to start defending their RMM software. Read more at Dark Reading.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar