Huntress has released the inaugural Huntress Tragic Quadrant, a comprehensive report that ranks various cyber tactics detected and neutralized by its Security Operations Center (SOC), against a metric defined as the "pucker factor." This term refers to how close each tactic brings an organization to experiencing significant damage when executed. The report is underscored by an impressive dataset, gathered from over 5 million endpoints and approximately 15 million identities across nearly 300,000 organizations.
Among the significant findings that have emerged from this report is the alarming statistic that, in the first quarter of 2026, a staggering 45% of endpoint-related incidents investigated by Huntress involved the abuse of Remote Monitoring and Management (RMM) tools. This dramatic increase marks a turning point in the landscape of cybersecurity threats, highlighting a clear pattern of misuse of legitimate tools.
RMM abuse has surged by an astonishing 277% year-over-year in 2025, solidifying its position as the most common threat type observed on endpoints by Huntress. These tools, which are typically trusted and legitimate, enable attacker activity to masquerade as normal administrative behavior, complicating detection efforts. In one notable incident, a fraudulent service agreement led to the installation of Tiflux, which then stealthily aggregated several remote access software—including UltraVNC, Splashtop, and ScreenConnect—on a single device. This arrangement provided attackers multiple avenues to regain access through a single phishing click.
Jamie Levy, Senior Director of Adversary Tactics at Huntress, encapsulated the rationale behind this tactic, stating, "Why would you spend the cycles to develop or build from scratch when you can use a legitimate tool that you can just pull off the shelf?"
The report also identifies identity-based tactics that share the high-risk “Oh $#!T” category alongside RMM abuse. For instance, mailbox manipulation—where malicious actors access inboxes to mark messages as read, delete incoming emails, and reroute communications to obscure folders—accounted for 24.6% of suspicious detection signals in the IT detection and response (ITDR) context for 2026. Additionally, Adversary-in-the-Middle (AiTM) account takeover attacks, which exploit session tokens en route to bypass multi-factor authentication, constituted 18.9% of identity-related threats in 2025.
A persisting trend in cyber threats is the simplicity of initial access methods. Approximately 70% of active intrusions identified by the Huntress SOC initiate through attackers authenticating via VPNs, often using valid credentials without the added security of a second authentication factor. Dray Agha, Senior Manager of Tactical Response at Huntress, cautioned that "Anything you expose to the internet will get hammered," with Remote Desktop Protocol (RDP) being particularly vulnerable.
In a related category, the report discusses tactics that, while infrequent, can lead to rapid escalation in impact severity. For example, ClickFix, a deceptive technique utilizing fake CAPTCHAs to entice users into executing harmful commands through the Windows Run box, made up only 2.2% of suspicious Endpoint Detection and Response (EDR) detection signals. Nevertheless, nearly 99% of these incidents were classified as high severity, with ClickFix accounting for over half (53.2%) of all malware loader activities observed in 2025.
Moreover, device code phishing experienced a staggering 1,380% increase in activity when comparing two six-month periods—from July to December 2025 to January to April 2026. A single phishing-as-a-service kit known as EvilTokens targeted 344 organizations across five countries in just 16 days utilizing legitimate infrastructure. Additionally, incidents involving bring-your-own-vulnerable-driver (BYOVD) EDR killers, although rare, proved highly impactful, with 23.8% of driver abuse incidents in 2025 linked to a single tool known as Throttlestop/RWDriver.
The report also highlights the issue of vulnerability exploitation, with attackers quickly weaponizing newly discovered flaws in software systems like Wing FTP Server, WSUS, and Gladinet CentreStack soon after disclosures. Muhammad Yahya Patel, a vCISO and cybersecurity advisor for EMEA at Huntress, warned that "the remediation window that defenders rely on, the gap between ‘patch available’ and ‘actively exploited at scale,’ is already measured in hours and days, and that gap will continue to narrow."
To bolster defenses against these concerning trends, Huntress advises organizations to rate and control their RMM tools, alert on unauthorized tools, baseline inbox rules, reduce session lifetimes, and necessitate re-authentication from new devices or locations, ensuring no remote access pathways depend on passwords alone.
In a future event scheduled for October 8, Huntress CEO Kyle Hanslovan is set to conduct a live hacking demonstration that will showcase techniques highlighted in the Tragic Quadrant, illustrating how quickly vulnerabilities can escalate from initial access to significant impacts. Interested participants can register for this instructive session through the Huntress website.
The findings laid out in the Huntress Tragic Quadrant serve as a crucial call to action for organizations striving to understand and mitigate the evolving landscape of cyber threats.

