RMM abuse found in 45% of Huntress endpoint incidents
Attackers relied on legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents Huntress recorded in the first quarter of 2026, according to a new report from the security company.
Huntress also placed 11 attack tactics on a chart that measures how often it sees each one and how much damage each can cause. RMM abuse sits farthest to the right, the spot reserved for the tactics observed most frequently.
IT departments use RMM tools to manage computers remotely. When an attacker installs one, they get persistent access and the ability to run commands, and that activity looks like normal administrator work. The rogue copy and the sanctioned one can behave in exactly the same way. Huntress describes the category as one hop from ransomware or data theft. The company says it grew 277% year over year in 2025.
One phishing click, four remote tools
In one case Huntress investigated, a fake service agreement installed an RMM tool called Tiflux. The intruder then added UltraVNC, Splashtop and ScreenConnect to the same machine. A single click gave the attacker several separate routes back in.
The researchers say attackers already use AI to write the fake document-share and service-agreement lures that start these intrusions.
"Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?" said Jamie Levy, senior director of adversary tactics at Huntress.
Huntress suggests a simple check. Ask the security team which RMM tools are approved, and what alerts them when an unapproved one shows up.
Inbox rules and stolen session tokens
Mailbox manipulation and account takeover share the same top-right corner of the chart.
In mailbox manipulation, an attacker who has access to an inbox creates a rule that moves a vendor's replies into a folder such as Archive, where they are easy to overlook. The attacker then swaps in an invoice that sends the payment somewhere else.
In adversary-in-the-middle (AiTM) takeovers, the attacker sits between the victim and the real Microsoft 365 login page and copies the session token. That token is the credential that keeps a user signed in. As long as the session remains valid, the attacker needs no password and does not trigger an MFA prompt.
Mailbox manipulation accounted for 19% of identity-based threats in 2025 and 24.6% of identity threat signals so far in 2026. AiTM made up 18.9% of identity-based threats in 2025. These numbers measure different things than the 45% RMM figure, which counts endpoint-related incidents, so they cannot be compared directly.
Huntress recommends asking IT how long sessions stay active and whether a new device or location forces a fresh login.
Device codes, ClickFix and a fake Claude download
Device code phishing lands in what Huntress calls the "low-key deadly" corner, for tactics it sees less often but that cause heavy damage. A fake workflow prompt sends the victim to Microsoft's genuine device code login page. Once the code is entered, the attacker holds an access token that can survive a password reset.
The researchers report a 1,380% year-over-year increase for this tactic. However, the comparison covers July through December 2025 against January through April 2026, and no starting count is given. The figure indicates direction but says nothing about volume. Separately, the EvilTokens phishing kit hit 344 organizations across five countries in 16 days.
ClickFix lures made up 53.2% of malware loader activity in 2025.
Huntress files AI platform abuse and deepfakes under "overhyped, for now." One AI platform case involved FakeAgent, which used a malicious Claude Artifact hosted on the real claude.ai domain. It sent people searching for Claude Desktop to SectopRAT and hit 29 organizations in two days. Six of the 11 tactics carry Huntress's marker for AI acceleration, including both of those.
Our Take
The common thread in the report is that the most frequent tactics do not depend on exploits or custom malware. They abuse things organizations already trust, such as admin tools, inbox rules, real Microsoft login pages and a genuine AI vendor's domain. This suggests that detection based on "is this software malicious?" will keep missing a large share of intrusions. The more useful question is whether this tool, rule or session should exist at all.
That also puts more weight on basic inventory. Huntress's suggested checks are modest: know which RMM tools are approved, know how long sessions last. It is worth noting that remote access software is also a patching concern in its own right, as seen when TeamViewer urged users to fix five severe flaws. Organizations that cannot list their remote tools may struggle with both problems.
Readers should treat the headline percentages with care. Huntress itself notes that the RMM, identity and device code figures measure different things, and the 1,380% jump comes without a baseline.
The AI angle is worth watching. Huntress labels AI platform abuse "overhyped, for now," yet flags six tactics as AI-accelerated. That fits a wider view that attackers currently lead defenders in using AI. It remains to be seen whether cases like FakeAgent stay rare, or whether that "for now" turns out to be the most important part of the label.
