RMM Abuse: How Cybercriminals Exploit Stealthy Attacks That Mimic Normal Operations

www.news4hackers.com-rmm-abuse-how-cybercriminals-exploit-stealthy-attacks-that-mimic-normal-operations-rmm-abuse-how-cybercriminals-exploit-stealthy-attacks-that-mimic-normal-operations

Huntress reported that 45% of endpoint-related incidents analyzed in the first quarter of 2026 involved the exploitation of legitimate remote monitoring and management (RMM) software.

RMM Abuse: A Covert Entry Point

Huntress evaluated 11 attack methods based on frequency and impact, placing RMM abuse in the highest-risk category. These tools, designed for remote system administration, grant adversaries persistent access and command execution capabilities that mimic standard administrative tasks. The malicious implementation often mirrors the behavior of authorized versions, making detection challenging. A single compromised endpoint can lead to multiple backdoors.

Case Study: Tiflux RMM and UltraVNC

In one instance, a phishing attack delivered a counterfeit service agreement that deployed the Tiflux RMM tool, followed by the installation of UltraVNC, Splashtop, and ScreenConnect on the same device. Attackers leverage artificial intelligence to generate convincing phishing lures such as fake document-sharing requests or service agreements.

Jamie Levy, senior director of adversary tactics at Huntress, noted that adversaries prioritize efficiency by utilizing pre-existing legitimate tools rather than developing custom solutions.

Mailbox Manipulation and Adversary-in-the-Middle (AiTM) Attacks

Mailbox manipulation and account takeover tactics share similar risk profiles. In mailbox manipulation scenarios, attackers create rules to divert vendor communications to hidden folders, enabling them to intercept and alter critical messages like invoices. AiTM attacks involve intercepting Microsoft 365 login sessions to capture session tokens, allowing unauthorized access without requiring passwords or triggering multi-factor authentication prompts.

Statistical Insights

Huntress data indicates that mailbox manipulation accounted for 19% of identity-based threats in 2025 and 24.6% of identity threat signals in 2026. AiTM threats represented 18.9% of identity-based attacks in 2025. These metrics differ from the 45% RMM incident rate, which focuses on endpoint compromises rather than identity-related breaches.

Phishing Techniques Targeting Device Authentication

Phishing techniques targeting device authentication codes fall into a category of low-frequency but high-impact attacks. A fake workflow prompt may redirect users to a legitimate Microsoft device code login page, where entering the code grants attackers an access token capable of bypassing password resets. Huntress documented a 1,380% year-over-year increase in such incidents between July 2025 and April 2026, though the lack of baseline data limits volume interpretation.

EvilTokens and ClickFix Malware

The EvilTokens phishing kit compromised 344 organizations across five countries within 16 days. ClickFix malware loaders accounted for 53.2% of malware distribution activity in 2025.

AI-Driven Attacks and Emerging Threats

AI-driven attacks, including deepfake and platform abuse cases, are categorized as “overhyped” but remain under active monitoring. A notable example involved the FakeAgent malware, which used a malicious Claude Artifact hosted on claude.ai to redirect users to SectopRAT, affecting 29 organizations in two days. Six of the 11 tracked tactics show signs of AI acceleration, including these cases.

Recommendations for Enterprise Security

Enterprise security teams must prioritize visibility into RMM tool usage, mailbox configurations, and authentication protocols. The integration of AI in both defensive and offensive strategies underscores the need for adaptive threat detection frameworks.



About Author

en_USEnglish