Remote Tool Abuse Surged 277% for Managed IT Providers

Managed service providers must harden remote-management tools to stop persistent access by cyber attackers.

Updated on Oct. 1, 2026 in Remote Work

Remote Tool Abuse Surged 277% for Managed IT Providers

Live Poll

Do you trust that common workplace software tools are secure enough against modern cyber threats?

Cybersecurity firm Huntress reported a 277% year-over-year increase in the abuse of remote monitoring and management (RMM) tools by attackers in 2025. These tools, which allow IT providers to manage customer environments, were implicated in 45% of all endpoint-related incidents during the first quarter of 2026.

Why it matters

Attackers target RMM platforms to gain persistent command capabilities within customer environments, creating significant security vulnerabilities for businesses reliant on outsourced IT. The shift toward intercepting session tokens for authentication bypass has made current defenses like multifactor authentication insufficient.

The study analyzed telemetry from 15 million identities across 300,000 organizations. It found that mailbox manipulation comprised 24.6% of identity threats in 2026, while adversary-in-the-middle attacks accounted for 18.9% of such threats in 2025.

The players

Huntress

A cybersecurity firm that provides managed security services and threat detection software for small-to-medium business environments.

The details

Attackers compromise networks by installing remote-access software like Tiflux, UltraVNC, Splashtop, and ScreenConnect, often masquerading as legitimate service agreements. Once inside, they perform adversary-in-the-middle attacks to intercept valid session tokens, effectively bypassing multifactor authentication. This strategy provides persistent administrative access that remains difficult for standard security monitoring to detect.

Timeline

  1. 2025: Remote management and adversary-in-the-middle threats were observed by Huntress.

  2. Q1 2026: Remote management abuse appeared in 45% of endpoint-related incidents.

  3. 2026: Mailbox manipulation emerged as a major identity threat signal.

Market Landscape

This development marks an acceleration of the industry trend toward exploiting trusted management platforms for persistence. It follows a pattern set by recent adversary-in-the-middle campaigns that leverage session token theft to bypass conventional authentication.

Business operators should audit all third-party managed service providers to verify how they secure remote-management access and monitor for unauthorized session tokens. Ensure that specific policies are in place to vet any remote-monitoring software installations on enterprise endpoints.

The takeaway

The rise in RMM abuse confirms that trust in management software has become a significant liability that requires stricter oversight. Operators should review their IT service contracts to mandate clear, verifiable reporting on which remote access tools are deployed and monitored within their infrastructure.

Further reading

For more on securing distributed business systems, visit the Remote Work section.

Source note: This article includes information reported by Channel Insider.

Live Poll

Do you trust that common workplace software tools are secure enough against modern cyber threats?