Skip to content

Image: img.helpnetsecurity.com · rights & removal

Executive Summary

Attackers are utilizing legitimate Remote Monitoring and Management (RMM) software in 45% of endpoint-related incidents recorded in the first quarter of 2026. Attackers leverage RMM tools, which IT teams use for management, to gain persistent access and remote command execution that appears as normal administrator activity. This abuse is categorized as one hop from ransomware or data theft and has seen a 277% year-over-year increase in 2025. Attackers can use malicious copies alongside approved versions to achieve similar outcomes. Furthermore, mailbox manipulation accounts for 19% of identity-based threats and 24.6% of identity threat signals so far in 2026. Adversary-in-the-middle (AiTM) takeovers involve session token theft, allowing attackers to maintain a signed-in state without needing passwords or MFA prompts. Device code phishing shows a 1,380% year-over-year increase in related activity.

Facts Only

* Attackers used legitimate RMM software in 45% of endpoint-related incidents in Q1 2026.
* RMM abuse grants attackers persistent access and remote command execution that mimics administrator work.
* A fake service agreement installed an RMM tool called Tiflux, allowing attackers to stack tools like UltraVNC, Splashtop, and ScreenConnect on one device via a phishing click.
* Mailbox manipulation accounted for 19% of identity-based threats in 2025 and 24.6% of identity threat signals so far in 2026.
* Adversary-in-the-middle (AiTM) takeovers involve stealing session tokens, bypassing the need for passwords or MFA prompts.
* Device code phishing saw a 1,380% year-over-year increase between July–December 2025 and January–April 2026.
* FakeAgent used a malicious Claude Artifact hosted on the real claude.ai domain to direct users seeking Claude Desktop to SectopRAT, hitting 29 organizations in two days.
* ClickFix accounted for 53.2% of malware loader activity in 2025.

Full Take

The integration of legitimate enterprise tools into the attack surface represents a significant shift from purely malicious tool usage to leveraging established trust relationships. The ease with which attackers can embed themselves within RMM frameworks exploits organizational reliance on administrative workflows, effectively weaponizing the concept of "business as usual." This pattern suggests that security defenses must evolve beyond signature-based detection to scrutinize the context and behavior inherent in legitimate system activities. Simultaneously, the observed manipulation of identity layers through session token theft and mailbox rule changes highlights a systemic vulnerability where authentication mechanisms are bypassed by exploiting established trust sessions rather than credential compromise alone. The growth in AI-assisted delivery, evidenced by fake artifacts leveraging real platform domains, implies that the sophistication of delivery is accelerating faster than traditional defensive frameworks can adapt. The key implication for agency is the necessity to establish verification protocols not just around external access points but within the operational integrity of core management systems, prompting questions about where accountability resides when tools designed for legitimate oversight become vectors for compromise. What measures are in place to verify the provenance and intent behind all remote management commands? How can security postures be assessed when the threat vector is woven into accepted administrative functions?

From the original · Help Net Security

Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The security company also ranked 11 attack tactics by how often it sees them and how much damage each can do, and RMM abuse sits farthest right on the chart, the position for tactics it sees most often.
Read the full story at helpnetsecurity.com

Sentinel — Human

Confidence

The text appears to be a well-structured analysis drawing from specific threat intelligence reports, characterized by careful integration of technical findings and strategic implications rather than pure synthetic generation.

Signals Detected
low severity: Sentence length variance shows some variation, but the flow remains somewhat dense and report-like.
low severity: The text flows logically from RMM abuse to identity threats and then specific attack tactics, demonstrating a unified analytical thread.
low severity: Data points (percentages, growth rates) are presented with necessary caveats regarding methodology (e.g., citing different metrics), which suggests human synthesis rather than raw data dumping.
low severity: The inclusion of specific, potentially proprietary or recently released research findings ('Huntress,' 'Q1 2026') anchors the content in verifiable sources, mitigating high fabrication risk.
Human Indicators
The text shifts between broad statistical statements and highly specific, jargon-heavy case examples (Tiflux, FakeAgent) which suggests an insider's perspective or close editorial synthesis.
The explicit acknowledgment of data limitations ('no starting count is given') demonstrates analytical awareness beyond simple reporting.
How RMM abuse gives attackers a way in that looks like business as usual | Huntaegis