The headline number comes from remote monitoring and management (RMM) software, the remote-control layer the MSP business runs on. According to IT Security Guru, in Q1 2026, 45% of endpoint-related incidents Huntress investigated involved abuse of remote monitoring and management (RMM) tools. The same report says RMM abuse jumped 277% year over year in 2025 and is now the single most common threat category Huntress sees on endpoints.
How the Tragic Quadrant works
The name pokes fun at analyst "magic quadrant" charts, but the method is simple. Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls "pucker factor": how close each tactic puts an organisation to major damage once it lands.
- Horizontal axis: how often Huntress sees the tactic across its monitored environments.
- Vertical axis: how close the tactic gets a victim to ransomware, data theft or business email compromise (BEC).
- Top-right corner: Huntress calls it the "OH $#!T" corner. Tactics there are both common and close to serious damage, and the company says to fix those first.
The data comes from telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 organisations. Huntress says it combined detections and incidents from 2026 so far, its 2026 Cyber Threat Report, and real cases its SOC investigated in partner and customer environments.
A caveat before going further: every number here comes from Huntress' own customers and its own detection definitions. Huntress protects a lot of organizations, but the data isn't a random sample of all businesses. Treat the percentages as a good picture of what one large MDR provider is seeing, not as industry-wide rates.
Section summary: The quadrant ranks attacks by how common they are and how much damage they do. The urgent corner contains RMM abuse, mailbox manipulation and adversary-in-the-middle (AiTM) account takeover.
RMM abuse: the MSP's own tool turned against it
RMM platforms do exactly what attackers want. They give persistent access, run remote commands, survive reboots and look normal to most security tools. As IT Security Guru puts it, because the tools are legitimate and already trusted, attacker activity can look like ordinary administration.
The case Huntress highlights shows why one rogue install is rarely the end of it. In one case, a fake service agreement installed Tiflux before quietly stacking UltraVNC, Splashtop and ScreenConnect on the same device, giving the attacker multiple ways back in from a single phishing click. That makes four remote-access paths from one lure. Remove one tool and the attacker still has three ways back in.
None of those products is malicious in itself, and each has plenty of legitimate users. The real question for an MSP is narrower: was this tool approved for this customer and this device, and is it behaving the way your technicians normally use it?
Why the RMM percentages don't match
Readers following Huntress will have seen several different RMM figures, which can look contradictory. They aren't. They measure different things:
| Huntress figure | What it measures |
|---|---|
| 45% | Endpoint-related incidents investigated in Q1 2026 (Tragic Quadrant) |
| "Nearly a quarter" | All incidents investigated, per the 2026 Cyber Threat Report |
| "Almost 40%" | Incidents handled by Huntress' Tactical Response team, per a recent company blog |
| 277% | Year-over-year growth in RMM abuse during 2025 |
The Cyber Threat Report figure is confirmed by IT Security Guru's earlier coverage, which said Huntress found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company. In a separate post last month, Huntress said its Tactical Response team now sees it in almost 40% of the incidents we investigate. The figures differ because each one is measured against a different set of incidents. On every measure, though, RMM abuse is rising.
This lines up with Huntress' recent field reports. In September, its researchers described browser-in-the-browser phishing pages where rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.
Section summary: RMM abuse is Huntress' most common endpoint threat. Attackers often install several remote tools for redundancy, so the realistic fix is tighter control over RMM, not dropping it.
Identity attacks: MFA was never the last line
The other two techniques in the top corner target identities rather than endpoints. Both work after the attacker is already signed in.
Mailbox manipulation
Mailbox manipulation, where an adversary with inbox access marks messages as read, deletes inbound mail and redirects emails into obscure folders such as RSS Feeds or Archive, accounted for 24.6% of suspicious ITDR detection signals so far in 2026. No malware is needed and no exploit runs. The attacker creates an inbox rule so the real vendor's "did you change your bank details?" reply goes to a folder nobody opens. That leaves room for invoice fraud and payment redirection.
That 24.6% is a share of Huntress' identity threat detection and response (ITDR) signals. It isn't a share of all incidents or all accounts.
AiTM account takeover
Adversary-in-the-middle (AiTM) account takeover, which steals session tokens in transit and sidesteps MFA, made up 18.9% of identity-based threats in 2025. Huntress describes the attacker sitting between the victim and a real Microsoft 365 sign-in page, passing the login through and capturing the session token. While that token stays valid, the attacker has access without needing the password again or a new MFA prompt.
The takeaway is not that MFA is useless. Phishable MFA protects the sign-in, but the attacker is stealing what comes after the sign-in. A completed MFA challenge tells you the user authenticated. It doesn't tell you the session that follows belongs to them.
Section summary: Mailbox rules and stolen session tokens let attackers stay inside Microsoft 365 quietly. Monitoring has to continue after the user signs in.
The other corners: ClickFix, device codes and AI
Huntress puts several popular techniques outside its top corner. That doesn't mean they're harmless.
- Device-code phishing ("low-key deadly"): The victim is persuaded to enter a short code on a real Microsoft page, which gives the attacker a token. Huntress reports that one phishing-as-a-service kit, EvilTokens, hit 344 organizations in five countries in 16 days. It used infrastructure hosted on Railway, a legitimate developer platform, and wrapped its links in legitimate Cisco, Trend Micro and Mimecast redirect URLs. The usual "check the URL" advice doesn't help when the sign-in page is genuinely Microsoft's.
- ClickFix (a daily pest with high stakes): ClickFix detections make up about 2.2% of managed EDR detection signals, but nearly 99% of those detections are rated high severity. A fake CAPTCHA tells the user to press Win+R and paste a command into the Windows Run box. One Huntress example ended with a LummaC2 infostealer infection.
- AI platform abuse ("overhyped, for now"): Channel Insider says Huntress also puts deepfake and voice-phishing attacks in this category. The reason is that it hasn't seen them cause widespread damage at the rate of the top-corner techniques. Huntress does cite FakeAgent, which used a malicious Claude Artifact hosted on the real claude.ai domain to deliver SectopRAT to 29 organizations in two days.
"For now" is doing real work in that label. Channel Insider reports that Huntress has observed attackers using AI-generated RMM phishing lures, while its research into device-code phishing found that attackers use AI to build phishing infrastructure and automate analysis of compromised inboxes. So far, AI is making existing attacks faster and more convincing. It hasn't replaced them.
Section summary: Device-code phishing, ClickFix and AI-assisted lures sit outside the top corner, but each is changing quickly and needs a plan.
A practical checklist for MSPs and Windows admins
Huntress' own advice is short: know which tools are approved, monitor mailbox rules, and catch strange session behavior. Here's how that translates into work. The Microsoft-specific items below are standard industry practice, not configurations Huntress prescribed.
- Build an RMM allowlist for each customer. Record which remote tools are approved, who can deploy them and on which devices. Earlier Huntress guidance says to restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients.
- Look for rogue copies of tools you already approved. An unknown ScreenConnect instance connecting to someone else's server is just as dangerous as an unknown product. Check where the client connects to, not just its name.
- Remove legacy RMM agents during onboarding. In earlier incident write-ups, Huntress described attackers getting in through a compromise of a legacy RMM that was in place prior to a business moving to a new MSP.
- Audit inbox rules regularly. In Exchange Online PowerShell,
Get-InboxRule -Mailbox user@domainlists a mailbox's rules. Look closely at rules that move mail into RSS Feeds, Archive or Conversation History, mark messages as read, or delete messages from specific senders. - Restrict device-code sign-ins where nobody needs them. Microsoft Entra Conditional Access can block the device code flow through its authentication flows condition. Most office workers never need it.
- Make stolen tokens harder to use. Phishing-resistant MFA such as passkeys or Windows Hello for Business, compliant-device requirements, and token protection all make a captured session much less useful.
- Handle ClickFix on Windows. Train users that no legitimate CAPTCHA ever asks them to press Win+R. Consider limiting the Run dialog and script interpreters for standard users where it won't break their work.
- Keep patching fast. Channel Insider includes rapid patching in its recommendations. The Huntress quadrant page itself focuses more on approved tools, mailbox rules and session behavior.
The balanced view
Huntress sells managed EDR, ITDR and RMM-control products, so it benefits when MSPs worry about these exact techniques. Its recent posts promote its own RMM inventory and app-control features alongside the research. That doesn't make the data wrong, and the case studies are specific and checkable. But MSPs should weigh the rankings against their own incident history before reorganizing their security plans around one vendor's chart.
The strongest point in the report is that attackers mostly don't need new techniques. They use your RMM agent, your Microsoft 365 sign-in page and your users' habit of pasting whatever they're told to paste. The fixes are unglamorous: know your tools, watch sessions after sign-in, and audit inbox rules.
References
- Huntress Tragic Quadrant Maps Top Cyber Risks for MSPs Channel Insider · 2026-10-01T13:00:00+00:00
- Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses | Huntress huntress.com
- Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses daily.dev