Huntress Reported Remote Management Tool Abuse Rise
New research identifies remote access tools and session interception as primary threats to managed service providers.
Updated on Oct. 1, 2026 in Remote Work

Live Poll
Do you trust that common workplace software tools are secure enough against modern cyber threats?
Huntress has released research showing that remote monitoring and management (RMM) tool abuse has become a leading cybersecurity risk. The study indicates that attackers are increasingly using these platforms to gain persistent access to customer environments.
Why it matters
Managed service providers remain a prime target because compromised remote management platforms provide attackers with command capabilities across a wide range of customer networks. These tactics allow malicious actors to maintain long-term access while bypassing traditional security defenses.
The report analyzed 5 million endpoints and 15 million identities across 300,000 organizations to track emerging threats. It found that remote monitoring and management abuse surged 277% year-over-year in 2025.
The players
Huntress
Huntress is a cybersecurity firm that specializes in managed detection and response for small to mid-sized businesses and their service providers.
The details
Attackers exploit these tools to install unauthorized software, including Tiflux, UltraVNC, Splashtop, and ScreenConnect, by utilizing fake service agreements. Furthermore, adversaries are increasingly executing adversary-in-the-middle attacks to intercept valid session tokens, effectively bypassing multifactor authentication protocols.
Timeline
2025: Remote management abuse increased by 277% year-over-year.
2025: Adversary-in-the-middle attacks represented 18.9% of identity threats.
Q1 2026: Remote management abuse accounted for 45% of endpoint-related incidents.
2026: Mailbox manipulation grew to represent 24.6% of identity threat signals.
Market Landscape
This finding reflects a broader shift toward targeting the trusted infrastructure that managed service providers use to administer remote networks. By weaponizing these remote management platforms, attackers are effectively scaling their access across entire customer bases simultaneously.
Businesses should audit their remote access software for unauthorized tools and ensure that monitoring logs are reviewed for anomalous session activity. Enhanced scrutiny of service agreements is critical to preventing attackers from using legitimate platforms to gain persistent access.
The takeaway
Security teams must prioritize monitoring for session token theft to protect against bypasses of multifactor authentication. Organizations should implement stricter validation processes for any software installed via remote management channels to close common entry points.
Further reading
For more information on securing distributed systems, visit our Remote Work section.
Live Poll
Do you trust that common workplace software tools are secure enough against modern cyber threats?







