How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers used legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. The company ranked 11 attack tactics by frequency and damage, placing RMM abuse as the most-seen tactic. Because IT teams use RMM tools for legitimate remote administration, malicious use blends in as business as usual.