Huntress: RMM abuse behind 45% of endpoint incidents
Huntress found attackers used legitimate remote monitoring and management (RMM) software in 45% of endpoint-related incidents in Q1 2026. The tactic grew 277% year over year in 2025, giving persistent access and remote command execution that mimics routine admin work.
- RMM abuse in 45% of endpoint incidents in Q1 2026
- Tactic grew 277% year over year in 2025
- Mailbox manipulation at 24.6% of identity threat signals in 2026
- Device code phishing up 1,380% year over year
Read next
Security