
Defenders get a clearer picture of the threats hitting endpoints after a Q1 2026 analysis that ranked 11 attack tactics by frequency and damage. Remote monitoring and management (RMM) abuse sat at the top of that chart, appearing in 45% of endpoint-related incidents recorded during the quarter, and the same report also tracked the sharp rise of mailbox manipulation, adversary-in-the-middle (AiTM) session theft, and device code phishing across the same period.
What RMM abuse looks like in practice
RMM tools let IT teams manage computers remotely, so an attacker who quietly installs one on a target machine gains persistent access and the ability to run commands as if they were a normal administrator. The activity blends in with routine operations and is hard to flag without knowing which tools are approved in the environment. The analysis recorded a 277% year over year increase in this tactic through 2025, a category Huntress describes as one hop from ransomware or data theft.
In a single engagement, a fake service agreement installed a legitimate RMM product called Tiflux, and the attacker then added UltraVNC, Splashtop, and ScreenConnect on the same endpoint. One phishing click gave the intruder four different remote access paths to the same machine. The same case pattern shows up across incidents: a legitimate remote tool, layered with more remote tools, all behaving like approved software.
Mailbox manipulation and AiTM account takeover
Two identity-focused tactics sit alongside RMM abuse in the highest-frequency, highest-damage corner of the chart. In mailbox manipulation, an attacker who has access to an inbox creates a rule that sends a vendor’s replies to a folder such as Archive, where they are easy to miss, then swaps in a fraudulent invoice that redirects payment. The legitimate thread keeps moving, and the change stays hidden inside the mailbox.
In AiTM takeovers, the attacker positions themselves between a victim and the real Microsoft 365 login page, and copies the session token that keeps a user signed in. While that session remains valid, the attacker needs no password and triggers no MFA prompt. Mailbox manipulation accounted for 19% of identity-based threats in 2025 and 24.6% of identity threat signals recorded so far in 2026. AiTM made up 18.9% of identity-based threats in 2025. The identity figures count different items than the 45% RMM figure, which counts endpoint-related incidents, so they are not directly comparable.
Device code phishing and the low-volume, high-damage corner
Device code phishing falls into what the report labels the low-key deadly corner: tactics that appear less often but cause heavy damage. A fake workflow prompt sends the victim to Microsoft’s real device code login page, and once the user enters the code, the attacker holds an access token that can survive a password reset. The report flags a 1,380% year over year increase, comparing July through December 2025 with January through April 2026, with no starting count given, so the figure shows direction rather than volume.
The EvilTokens phishing kit reached 344 organizations across five countries in 16 days. ClickFix accounted for 53.2% of malware loader activity in 2025. The analysis places AI platform abuse and deepfakes in an overhyped category for now, but one example shows how real the risk already is. FakeAgent used a malicious Claude Artifact hosted on the real claude.ai domain to redirect people looking for Claude Desktop to SectopRAT, reaching 29 organizations in two days. Six of the 11 tracked tactics carry a marker for AI acceleration, including both the device code and FakeAgent cases.
What defenders can ask the security team today
Two practical checks come out of the report. First, ask which RMM tools are approved in the environment and what would tip the team off if an unapproved one appeared on an endpoint. Second, ask how long active sessions stay valid and whether a new device or location forces a fresh login, which limits how long a stolen session token remains useful.
FAQ
What is RMM abuse?
RMM abuse is when an attacker installs a legitimate remote monitoring and management tool on a target machine to gain persistent access and run commands, which makes their activity look like ordinary administrator work. The Q1 2026 analysis found RMM abuse in 45% of endpoint-related incidents.
What is adversary-in-the-middle (AiTM) account takeover?
AiTM account takeover is when an attacker positions themselves between a user and the real Microsoft 365 login page, copies the session token that keeps the user signed in, and uses it until the session expires. While the session is valid, the attacker needs no password and triggers no MFA prompt. AiTM made up 18.9% of identity-based threats in 2025.
What is device code phishing?
Device code phishing tricks a user into entering a code on Microsoft’s real device code login page through a fake workflow prompt. Once the code is entered, the attacker holds an access token that can survive a password reset. The Q1 2026 analysis reported a 1,380% year over year increase in this tactic.
This article summarizes reporting from helpnetsecurity.com.
