Unauthorized use of remote management tools jumped 277% year-over-year in 2025 and played a role in 45% of endpoint-related incidents during the first quarter of 2026, according to new research from Huntress that maps cyberattack methods by frequency and potential for serious organizational harm. The "Tragic Quadrant" analysis, which examined telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 protected organizations, warns that many of the most damaging attacks aren't using novel techniques but instead exploiting trusted technologies already present in business environments.

Mailbox manipulation accounted for 24.6% of identity threat signals observed by Huntress in 2026, while adversary-in-the-middle attacks represented 18.9% of identity-based threats tracked in 2025. Once attackers gain access to an account, they can establish inbox rules that hide messages, alter vendor communications, or enable business email compromise without introducing malware. One investigation detailed in the report showed how a fraudulent service agreement resulted in Tiflux being installed on a device, followed by UltraVNC, Splashtop, and ScreenConnect, giving the attacker multiple pathways for ongoing access. Remote management platforms offer technicians persistent access and remote command capabilities across customer environments, but those same capabilities can make unauthorized use hard to separate from legitimate administrative work.

The report places AI platform abuse and deepfake or voice-phishing attacks in its "overhyped, for now" category because Huntress has not yet seen them inflicting widespread damage at the same rate as higher-priority methods. That doesn't mean AI can be dismissed entirely. Huntress has documented attackers using AI-generated RMM phishing lures, and its research into device-code phishing discovered that adversaries use AI to construct phishing infrastructure and automate examination of compromised inboxes.

The findings point managed service providers toward addressing vulnerabilities in everyday business technology rather than focusing exclusively on exotic new attack vectors. Adversary-in-the-middle attacks let attackers intercept a valid session token during authentication, enabling account access even after a victim has successfully completed multifactor authentication, which means identity protection can't stop at MFA deployment. The report ultimately directs MSPs toward a risk-based security approach: create an inventory of legitimate remote-management tools, monitor identities after authentication, strengthen mailbox and access configurations, and maintain rapid patching processes. AI may make attackers faster and their lures more convincing, but for now, many of the most consequential attacks are still succeeding by turning everyday business technology against the organizations that trust it. For channel partners balancing client expectations with operational reality, the choice between comprehensive monitoring and cost containment will shape not just security posture but also liability exposure when breaches inevitably occur.