Attackers Exploit Legitimate RMM Tools for Persistent Access
Threat actors are increasingly abusing Remote Monitoring and Management (RMM) software, making it the most damaging and frequently observed attack tactic, according to Huntress.

Legitimate Remote Monitoring and Management (RMM) software is becoming a favored tool for cybercriminals, accounting for a significant 45% of endpoint-related incidents tracked by security firm Huntress in the first quarter of 2026. This tactic has surged in popularity, jumping a staggering 277% year-over-year in 2025, and is now ranked as the most frequently observed and damaging attack method by the firm.
RMM tools are designed to allow IT professionals to manage computers remotely, providing capabilities for system maintenance, software deployment, and troubleshooting. However, when compromised, these same functionalities offer attackers a powerful avenue for persistent access and remote command execution. The malicious use of RMM software is particularly insidious because the activity often blends seamlessly with legitimate IT operations, making it difficult for security teams to distinguish between authorized administrative tasks and malicious intrusions.
Attackers are employing various methods to deploy these RMM tools. One observed technique involves tricking victims into installing malicious software disguised as legitimate service agreements. In one documented case, a single phishing click led to the installation of an RMM tool named Tiflux, which was then augmented with additional remote access tools like UltraVNC, Splashtop, and ScreenConnect. This layered approach provides attackers with multiple backdoors into a compromised system, increasing their chances of maintaining access even if one tool is detected and removed.
The ease with which attackers can leverage existing, trusted software is a key driver of this trend. "Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?" noted Jamie Levy, senior director of adversary tactics at Huntress. This "off-the-shelf" approach significantly lowers the barrier to entry for sophisticated attacks, allowing threat actors to focus on evasion and exploitation rather than tool development.
To combat this growing threat, Huntress suggests that organizations implement strict controls and awareness programs. A crucial step is for security teams to maintain an up-to-date inventory of all approved RMM tools and to educate employees on how to identify and report any unapproved software installations. Regular audits and network monitoring can help detect the presence of unauthorized RMM agents.
Beyond RMM abuse, the Huntress report also highlights other high-impact tactics, including mailbox manipulation and adversary-in-the-middle (AiTM) account takeovers. Mailbox manipulation involves attackers creating hidden inbox rules to intercept vendor communications and redirect payments, while AiTM attacks capture session tokens to bypass multi-factor authentication. These identity-based threats, though distinct from RMM abuse in their metrics, represent other critical areas of concern for organizations.
Furthermore, the report touches upon "device code phishing" and AI-accelerated attacks. Device code phishing, which has seen a dramatic increase, tricks users into granting access tokens that persist even after a password reset. While AI and deepfakes are currently considered "overhyped for now" by Huntress, the firm acknowledges that six of the eleven tactics analyzed show signs of AI acceleration, indicating a growing role for artificial intelligence in both attack and defense strategies.
The increasing reliance on legitimate tools by attackers underscores a shift in the threat landscape, where the lines between legitimate software and malicious tools are becoming increasingly blurred. This necessitates a proactive and adaptive security posture, focusing on comprehensive endpoint visibility, strict software control, and continuous user education to mitigate the evolving risks.