Security1 publisher2 min readPublished
Attackers used legitimate remote management tools in 45% of endpoint incidents Huntress logged
Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Huntress says RMM abuse rose 277% year over year in 2025 and describes the category as one hop from ransomware or data theft.
- In one case a fake service agreement installed the Tiflux RMM tool, and the intruder then added UltraVNC, Splashtop and ScreenConnect to the same device.
- Of the 11 attack tactics Huntress charted by frequency and damage, RMM abuse is the one it sees most often.
- Mailbox manipulation and adversary-in-the-middle account takeover sit in the same top-right corner of Huntress's chart as RMM abuse.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Alerting on remote-access activity alone fires on IT's own agents as readily as on an intruder's, so it cannot be the control that separates the two.
- exposure One phishing click left four remote tools on one host, so a cleanup that removes the first agent found leaves the intruder three other ways back in.
- decision Security teams need a named inventory of sanctioned RMM products, because without one an unapproved Tiflux or UltraVNC install has nothing to be checked against.
An attacker who installs an RMM agent gets persistent access and remote command execution, and the activity looks like ordinary administrator work [5]. Huntress says the malicious copy and the approved one can behave the same way [4].
Jamie Levy, senior director of adversary tactics at Huntress, said: "Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?" [9]
Huntress suggests asking the security team two things: which RMM tools are approved, and what tips them off when an unapproved one appears [10]. A list of approved products catches software the organization never bought. It does less when the intruder installs a brand IT already runs. The Tiflux chain included Splashtop and ScreenConnect [6], and Huntress says a rogue copy can behave like a sanctioned one [4]. In that case the difference was the entry point, a fake service agreement delivered through a phishing click [6] [7]. The report, as Help Net Security summarizes it, does not describe how to verify where an install came from.
The RMM figures cover two periods, all of 2025 and the first quarter of 2026 [3] [1]. They describe a sustained pattern. FakeAgent, from the same report, is a single campaign: a malicious Claude Artifact hosted on the real claude.ai domain sent people looking for Claude Desktop to SectopRAT and hit 29 organizations in two days [15]. Huntress files AI platform abuse and deepfakes under "overhyped, for now" [15]. It marks six of its 11 tactics as AI-accelerated [16], and its researchers say attackers already use AI to write fake document-share and service-agreement lures [8].
The headline figures use different denominators. The 45% counts endpoint-related incidents. The mailbox manipulation and adversary-in-the-middle shares count identity threats and cannot be ranked against it [12]. Huntress reports a 1,380% rise in device code phishing, comparing July through December 2025 with January through April 2026, with no starting count given [13]. Help Net Security notes that without a base the figure shows direction, not volume [13]. The EvilTokens phishing kit comes with an actual count: 344 organizations across five countries in 16 days [14].
What to watch
- Whether Huntress publishes the starting counts behind the 1,380% device code phishing rise, which would show whether it reflects volume or a small base.
- Whether Huntress's next quarterly data keeps RMM abuse at or above 45% of endpoint-related incidents.
- Whether Huntress moves AI platform abuse out of its "overhyped, for now" category if campaigns like FakeAgent recur.