Image: img.helpnetsecurity.com · rights & removal
How RMM abuse gives attackers a way in that looks like business as usual
Reporting by Help Net SecurityRead the original at helpnetsecurity.com
Executive Summary
Facts Only
* Attackers used legitimate RMM software in 45% of endpoint-related incidents in Q1 2026.
* RMM abuse grants attackers persistent access and remote command execution that mimics administrator work.
* A fake service agreement installed an RMM tool called Tiflux, allowing attackers to stack tools like UltraVNC, Splashtop, and ScreenConnect on one device via a phishing click.
* Mailbox manipulation accounted for 19% of identity-based threats in 2025 and 24.6% of identity threat signals so far in 2026.
* Adversary-in-the-middle (AiTM) takeovers involve stealing session tokens, bypassing the need for passwords or MFA prompts.
* Device code phishing saw a 1,380% year-over-year increase between July–December 2025 and January–April 2026.
* FakeAgent used a malicious Claude Artifact hosted on the real claude.ai domain to direct users seeking Claude Desktop to SectopRAT, hitting 29 organizations in two days.
* ClickFix accounted for 53.2% of malware loader activity in 2025.
Full Take
From the original · Help Net Security
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The security company also ranked 11 attack tactics by how often it sees them and how much damage each can do, and RMM abuse sits farthest right on the chart, the position for tactics it sees most often.Read the full story at helpnetsecurity.com
Sentinel — Human
The text appears to be a well-structured analysis drawing from specific threat intelligence reports, characterized by careful integration of technical findings and strategic implications rather than pure synthetic generation.
