Legitimate remote monitoring and management software is becoming a favored way in, according to Huntress research reported by Help Net Security. The security company found RMM abuse in 45% of endpoint-related incidents it recorded in the first quarter of 2026, and says the tactic jumped 277% year over year in 2025. Because IT teams use RMM tools for remote administration, an attacker who installs one gets persistent access and remote command execution that can look like normal administrator work. Huntress places RMM abuse in the category of tactics it sees most often, calling it one step from ransomware or data theft.

One case shows how little effort is required: a fake service agreement installed the RMM tool Tiflux, and the intruder then added UltraVNC, Splashtop, and ScreenConnect on the same device. A single phishing click gave the attacker multiple ways back in. Huntress also flags mailbox manipulation and adversary-in-the-middle session-token theft as high-frequency, high-impact identity threats. Mailbox manipulation made up 19% of identity-based threats in 2025 and 24.6% of identity threat signals so far in 2026, while AiTM accounted for 18.9% in 2025. Those figures count identity-based threats, not endpoint incidents, so they cannot be ranked against the RMM number.

Device code phishing sits in a lower-frequency but high-damage category. Huntress reports a 1,380% increase, but the comparison covers July through December 2025 versus January through April 2026 with no starting count, so the figure shows direction rather than volume. The EvilTokens phishing kit hit 344 organizations across five countries in 16 days, and ClickFix made up 53.2% of malware loader activity in 2025. Huntress calls AI platform abuse and deepfakes overhyped for now, yet six of the 11 tracked tactics carry its AI acceleration marker, including FakeAgent, which used a malicious Claude Artifact on the real claude.ai domain to redirect people seeking Claude Desktop to SectopRAT, hitting 29 organizations in two days.