- In 45% of the endpoint-related incidents Huntress logged in Q1 2026, the attacker was running genuine remote management software.
- Attackers are borrowing trusted tools, logins and domains, so a clean scan proves little. The real question is whether the organisation approved the tool.
- Ask your security team which remote tools are approved, what flags an unapproved one, and how long sign-in sessions last.
Attackers are borrowing the tools you approved
Building tools from scratch takes effort. Huntress, a security company, says attackers increasingly reach for existing tools instead. They install the remote management software that IT teams already use.
Nearly half of the endpoint-related incidents Huntress logged in the first quarter of 2026 involved a genuine product of this kind. Endpoint means a laptop, desktop or server. The category is called RMM, short for remote monitoring and management. IT staff use it to control computers from anywhere.
The 45% is a share of the incidents Huntress itself recorded. It does not describe all attacks everywhere.
Huntress says RMM abuse jumped 277% year over year in 2025. Jamie Levy, its senior director of adversary tactics, explained the appeal as saving effort. Why spend time building a tool when a legitimate one is ready to take?
How one click becomes four back doors
Huntress described a case that began with a fake service agreement. Opening it installed an RMM tool called Tiflux. The intruder then added UltraVNC, Splashtop and ScreenConnect to the same device.
That is the mechanism worth understanding. Each tool gives remote control and a way to run commands. Together they give the attacker several ways back in. Removing one does not close the others.
The tools are not malware, so there is nothing obviously malicious to find. By Huntress's account, the copy an intruder installs and the one your IT team deployed can act alike. AI already helps with the bait too, the researchers say, including fake file-sharing notices and fake service contracts.
The same pattern shows up in logins
The idea is that attackers are borrowing our trust, not breaking it. The pattern repeats in the other tactics Huntress ranks.
Mailbox manipulation starts with access to someone's inbox. The attacker creates a rule that diverts a supplier's messages to a quiet folder such as Archive, where they are easy to miss. A doctored invoice then redirects the payment. Huntress puts its share of identity threat signals at 24.6% so far in 2026.
Adversary-in-the-middle attacks put the criminal between the victim and the genuine Microsoft 365 sign-in page. The attacker captures the session token, the digital proof that a user is already logged in. While that session is valid, no password or MFA prompt is needed.
Device code phishing works the same way. A fake workflow prompt sends someone to Microsoft's real device code page. The victim types in the code, and the attacker receives an access token. That token can outlast a password reset.
Huntress reports device code phishing rose 1,380%, comparing July to December 2025 with January to April 2026. It gives no starting count, so the figure shows direction, not volume.
Separately, Huntress reports that the EvilTokens phishing kit hit 344 organizations in five countries in 16 days.
Even the AI-linked case borrows. The FakeAgent campaign hid behind claude.ai itself. A malicious Claude Artifact published there steered people searching for Claude Desktop to SectopRAT. It hit 29 organizations in two days. Huntress still files AI platform abuse under "overhyped, for now." Six of its 11 tactics carry an AI-acceleration marker.
The percentages above count different things. The RMM figure counts endpoint incidents and the others count identity threats, so they cannot be ranked against each other.
What to ask your team this week
The lesson here is that "is this software bad?" is the wrong question. The useful one is "did we approve it?" That needs a list, and someone who owns it.
Huntress's researchers suggest two checks. First, get the list of remote tools IT has sanctioned, and learn what would raise an alarm if another one showed up. Second, ask how long a stolen login would keep working. Then ask whether a sign-in from an unfamiliar laptop or city makes the user prove who they are again.
A third question follows from the device code cases. Does anyone in the company need to sign in with a device code at all? If not, a prompt asking for one is worth treating as a flag.
If the intruder uses your tools, the only thing left to check is whether you invited them.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





