Full Report
The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data.
Analysis Summary
Based on the provided Huntress Tragic Quadrant report, here is the summary of the primary attack tools and techniques currently impacting businesses.
# Tool/Technique: RMM Abuse & Identity-Based Tactics (2026 Landscape)
## Overview
Attackers are increasingly moving away from "flashy" malware in favor of abusing legitimate Remote Monitoring and Management (RMM) tools and bypassing identity controls. These tactics are prioritized because they blend in with routine administrative behavior, making detection difficult for standard security tools.
## Technical Details
- **Type:** Tool Abuse (Living-off-the-Land) and Identity-based Techniques.
- **Platform:** Windows (Endpoints), Microsoft 365 / Cloud Identities.
- **Capabilities:** Persistence, remote command execution, MFA bypass, and mailbox manipulation.
- **First Seen:** Ongoing; data reflects spikes in Q1 2026.
## MITRE ATT&CK Mapping
- **[TA0003 - Persistence]**
- [T1219 - Remote Access Software]
- **[TA0006 - Credential Access]**
- [T1557 - Adversary-in-the-Middle]
- [T1528 - Steal Application Access Token]
- **[TA0007 - Discovery]**
- [T1114 - Email Collection]
- **[TA0005 - Defense Evasion]**
- [T1562.001 - Impair Defenses: Disable or Modify Tools]
## Functionality
### Core Capabilities
- **RMM Persistence:** Installation of unauthorized but legitimate tools (e.g., ScreenConnect, AnyDesk) to maintain access without triggering antivirus signatures.
- **AiTM (Adversary-in-the-Middle):** Using proxy servers to intercept credentials and Session Tokens in real-time to bypass Multi-Factor Authentication (MFA).
- **Mailbox Manipulation:** Creating hidden folder rules to divert communications, facilitating Business Email Compromise (BEC).
### Advanced Features
- **AI-Enhanced Lures:** Use of Generative AI to create highly convincing document shares, service agreements, and phishing lures.
- **Browser-in-the-Browser (BitB):** Simulating a fake browser window within a legitimate one to harvest credentials.
- **Device Code Phishing:** Abusing the OAuth 2.0 device authorization flow to gain access to corporate accounts without needing a password.
## Indicators of Compromise
- **File Names:** Look for unauthorized instances of `ScreenConnect.Client.exe`, `AnyDesk.exe`, or `AteraAgent.exe` in unexpected directories.
- **Network Indicators:**
- Connections to unauthorized RMM relay servers.
- Traffic to known AiTM proxy frameworks (e.g., `evilginx` instances - [defanged] `example-phish-domain[.]com`).
- **Behavioral Indicators:**
- Sudden creation of Outlook rules that move emails to the "Deleted Items" or "RSS Feeds" folders.
- Logins originating from ISP/VPN providers inconsistent with user history during MFA sessions.
- Use of `PowerShell` to download MSI installers for RMM tools.
## Associated Threat Actors
- **LUMMA (ClickFix variants)**
- **CL0P Ransomware Group** (Exploiting vulnerabilities like Gladinet CentreStack/Triofox)
- **General BEC Scammers and IABs (Initial Access Brokers)**
## Detection Methods
- **Behavioral Detection:** Monitoring for "off-hours" RMM activity or the execution of RMM installers from the `Downloads` or `Temp` folders.
- **Identity Analytics:** Identifying concurrent logins from geographically distant locations (Impossible Travel) or session token reuse.
- **SaaS Auditing:** Monitoring for unauthorized changes to mail flow rules or the addition of new MFA devices/trusted IPs.
## Mitigation Strategies
- **Application Blocklisting:** Use AppLocker or similar tools to prevent the execution of RMM software that is not officially sanctioned by the IT department.
- **Conditional Access:** Implement strict Conditional Access policies that require compliant, managed devices for access to sensitive resources.
- **Token Revocation:** Shorten session lifetimes to mitigate the impact of stolen session tokens.
- **Permission Hardening:** Regularly audit Microsoft 365 global admin roles and trim unnecessary permissions (Identity Hygiene).
## Related Tools/Techniques
- **ClickFix:** An emerging social engineering tactic that tricks users into running malicious code to "fix" a browser display error.
- **Webshells:** Malicious scripts uploaded to web servers (e.g., Parks and Rec Management platforms) to maintain server-side persistence.