Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls “pucker factor”: how close each tactic puts an organisation to major damage once it lands.
Built on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 organisations, the report includes several previously unpublished findings. Chief among them: in Q1 2026, 45% of endpoint-related incidents Huntress investigated involved abuse of remote monitoring and management (RMM) tools.

RMM abuse jumped 277% year over year in 2025 and is now the single most common threat category Huntress sees on endpoints. Because the tools are legitimate and already trusted, attacker activity can look like ordinary administration. In one case, a fake service agreement installed Tiflux before quietly stacking UltraVNC, Splashtop and ScreenConnect on the same device, giving the attacker multiple ways back in from a single phishing click.
“Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?” – Jamie Levy, Senior Director, Adversary Tactics, Huntress
Identity attacks sit alongside RMM in the danger zone
RMM abuse shares the report’s top-right “Oh $#!T” corner with two identity-based tactics. Mailbox manipulation, where an adversary with inbox access marks messages as read, deletes inbound mail and redirects emails into obscure folders such as RSS Feeds or Archive, accounted for 24.6% of suspicious ITDR detection signals so far in 2026. Adversary-in-the-middle (AiTM) account takeover, which steals session tokens in transit and sidesteps MFA, made up 18.9% of identity-based threats in 2025.
Initial access remains stubbornly simple. Roughly 70% of the active intrusions caught by the Huntress SOC start with adversaries authenticating through VPN access, often with valid credentials and no second factor.
“Anything you expose to the internet will get hammered. RDP sits at the top of that list.” – Dray Agha, Senior Manager, Tactical Response, Huntress
Low prevalence, high severity
The report also flags tactics that appear less often but escalate quickly. ClickFix, the fake CAPTCHA technique that tricks users into pasting malicious commands into the Windows Run box, made up just 2.2% of suspicious EDR detection signals, yet nearly 99% of those signals were high severity. ClickFix was also behind 53.2% of all malware loader activity in 2025.
Device code phishing rose 1,380% when comparing July to December 2025 with January to April 2026. A single phishing-as-a-service kit, EvilTokens, hit 344 organisations across five countries in 16 days using only legitimate infrastructure. Meanwhile, bring-your-own-vulnerable-driver (BYOVD) EDR killers remain rare but decisive, with 23.8% of driver abuse in 2025 traced to a single tool, Throttlestop/RWDriver. In one incident, an attacker entered through stolen SonicWall VPN credentials and loaded a 15-year-old revoked EnCase driver to kill 59 security processes from kernel mode.
Vulnerability exploitation also lands in the “Low-key deadly” corner, with Huntress observing attackers weaponise flaws in Wing FTP Server, WSUS and Gladinet CentreStack and Triofox within days of disclosure.
“The remediation window that defenders rely on, the gap between ‘patch available’ and ‘actively exploited at scale,’ is already measured in hours and days for the most critical vulnerabilities, and that gap will continue to narrow.” – Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress
Huntress recommends defenders start in the top-right corner: establish which RMM tools are approved and alert on anything else, baseline normal inbox rules, shorten session lifetimes and require re-authentication from new devices or locations, and ensure no remote access path relies on a password alone.
On 8 October, Huntress CEO Kyle Hanslovan will run a live hacking demonstration of techniques from the Tragic Quadrant, showing how quickly they move from initial access to impact. You can register here: https://www.huntress.com/upcoming-livestreams/live-hack-see-the-threats-that-topped-our-list





