RMM abuse found in 45% of Huntress endpoint incidents
Attackers relied on legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents Huntress recorded in the first quarter of 2026, according to a new report from the security company.
Huntress also placed 11 attack tactics on a chart that measures how often it sees each one and how much damage each can cause. RMM abuse sits farthest to the right, the spot reserved for the tactics observed most frequently.
IT departments use RMM tools to manage computers remotely. When an attacker installs one, they get persistent access and the ability to run commands, and that activity looks like normal administrator work. The rogue copy and the sanctioned one can behave in exactly the same way. Huntress describes the category as one hop from ransomware or data theft. The company says it grew 277% year over year in 2025.
