How RMM abuse gives attackers a way in that looks like business as usual
Huntress reports attacker RMM abuse in 45% of Q1 2026 endpoint incidents, up 277% YoY, delivered via phishing lures stacking multiple remote-access tools.
Huntress found attackers abusing legitimate remote monitoring and management (RMM) software in 45% of endpoint-related incidents in Q1 2026, a category that grew 277% year over year in 2025 and sits 'one hop from ransomware or data theft.' In one case a fake service agreement installed Tiflux, after which the intruder stacked UltraVNC, Splashtop, and ScreenConnect on the same device for redundant access. Identity attacks were also ranked: mailbox manipulation made up 19% of identity-based threats in 2025 (24.6% of 2026 signals so far), AiTM session-token theft 18.9%, and device code phishing rose 1,380% between measured periods, with the EvilTokens kit hitting 344 organizations across five countries in 16 days. FakeAgent abused a malicious Claude Artifact on the real claude.ai domain to push SectopRAT to 29 organizations in two days, and ClickFix accounted for 53.2% of malware loader activity in 2025.