International Cyber Expo International Cyber Expo
  • About Us
Thursday, 1 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

by Guru Writer
October 1, 2026
in Featured
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant
Share on FacebookShare on Twitter

Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls “pucker factor”: how close each tactic puts an organisation to major damage once it lands.

Built on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 organisations, the report includes several previously unpublished findings. Chief among them: in Q1 2026, 45% of endpoint-related incidents Huntress investigated involved abuse of remote monitoring and management (RMM) tools.

Huntress Tragic Quadrant

RMM abuse jumped 277% year over year in 2025 and is now the single most common threat category Huntress sees on endpoints. Because the tools are legitimate and already trusted, attacker activity can look like ordinary administration. In one case, a fake service agreement installed Tiflux before quietly stacking UltraVNC, Splashtop and ScreenConnect on the same device, giving the attacker multiple ways back in from a single phishing click.

“Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?” – Jamie Levy, Senior Director, Adversary Tactics, Huntress

Identity attacks sit alongside RMM in the danger zone

RMM abuse shares the report’s top-right “Oh $#!T” corner with two identity-based tactics. Mailbox manipulation, where an adversary with inbox access marks messages as read, deletes inbound mail and redirects emails into obscure folders such as RSS Feeds or Archive, accounted for 24.6% of suspicious ITDR detection signals so far in 2026. Adversary-in-the-middle (AiTM) account takeover, which steals session tokens in transit and sidesteps MFA, made up 18.9% of identity-based threats in 2025.

Initial access remains stubbornly simple. Roughly 70% of the active intrusions caught by the Huntress SOC start with adversaries authenticating through VPN access, often with valid credentials and no second factor.

“Anything you expose to the internet will get hammered. RDP sits at the top of that list.” – Dray Agha, Senior Manager, Tactical Response, Huntress

Low prevalence, high severity

The report also flags tactics that appear less often but escalate quickly. ClickFix, the fake CAPTCHA technique that tricks users into pasting malicious commands into the Windows Run box, made up just 2.2% of suspicious EDR detection signals, yet nearly 99% of those signals were high severity. ClickFix was also behind 53.2% of all malware loader activity in 2025.

Device code phishing rose 1,380% when comparing July to December 2025 with January to April 2026. A single phishing-as-a-service kit, EvilTokens, hit 344 organisations across five countries in 16 days using only legitimate infrastructure. Meanwhile, bring-your-own-vulnerable-driver (BYOVD) EDR killers remain rare but decisive, with 23.8% of driver abuse in 2025 traced to a single tool, Throttlestop/RWDriver. In one incident, an attacker entered through stolen SonicWall VPN credentials and loaded a 15-year-old revoked EnCase driver to kill 59 security processes from kernel mode.

Vulnerability exploitation also lands in the “Low-key deadly” corner, with Huntress observing attackers weaponise flaws in Wing FTP Server, WSUS and Gladinet CentreStack and Triofox within days of disclosure.

“The remediation window that defenders rely on, the gap between ‘patch available’ and ‘actively exploited at scale,’ is already measured in hours and days for the most critical vulnerabilities, and that gap will continue to narrow.” – Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress

Huntress recommends defenders start in the top-right corner: establish which RMM tools are approved and alert on anything else, baseline normal inbox rules, shorten session lifetimes and require re-authentication from new devices or locations, and ensure no remote access path relies on a password alone.

On 8 October, Huntress CEO Kyle Hanslovan will run a live hacking demonstration of techniques from the Tragic Quadrant, showing how quickly they move from initial access to impact. You can register here: https://www.huntress.com/upcoming-livestreams/live-hack-see-the-threats-that-topped-our-list

ShareTweet
Previous Post

Huntress and ALSO partner to put managed security in reach of more European MSPs

Recent News

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

October 1, 2026
Huntress and ALSO partner to put managed security in reach of more European MSPs

Huntress and ALSO partner to put managed security in reach of more European MSPs

October 1, 2026
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data

Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data

September 30, 2026
CyberASAP Secures £10m Boost as UK’s Next Wave of Cyber Innovators Take Centre Stage

CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation

September 30, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol