These questions come from security team Slack channels, vCISO office hours, and those 3pm meetings where someone asks, "Wait, how do we actually check this?" The answers below draw on Huntress's Q1 2026 incident data, which found attackers using legitimate RMM software in 45% of endpoint-related incidents, and on what works when you're trying to get ahead of these tactics without rebuilding your entire stack.
We already use RMM tools. How do we tell if someone installed a second one?
Start with an inventory. Ask your IT team which RMM platforms you've approved, like ScreenConnect or Datto RMM. Then check what's actually running. Endpoint Detection and Response tools should flag new remote-access software, but you need a baseline first.
In one case documented by Huntress, a fake service agreement installed Tiflux, and the attacker then layered UltraVNC, Splashtop, and ScreenConnect on the same device. One phishing click gave four ways back in. The malicious copy and the approved one behave identically, which is why this tactic is so common.
Your Endpoint Detection and Response policy should require approval for any remote-access binary. If your team can't answer "which RMM tools are approved and what tips us off when an unapproved one appears," you're running blind. RMM abuse jumped 277% year over year in 2025, and Huntress calls it one hop from ransomware or data theft.
Someone clicked a phishing link. What mailbox rules should we check?
Look for inbox rules that auto-forward, auto-delete, or auto-move messages to folders like Archive or RSS Feeds. Attackers create these rules to hide vendor replies after they've swapped in a fraudulent invoice.
Mailbox manipulation made up 19% of identity-based threats in 2025 and 24.6% of identity threat signals so far in 2026. The attacker doesn't need to stay in the mailbox; the rule does the work. You'll find these under Outlook's "Manage Rules & Alerts" or the equivalent in your mail client's server-side rule settings.
Check rules that:
- Move messages from known vendors to low-traffic folders
- Forward copies to external addresses
- Mark messages as read automatically
- Delete messages matching certain keywords
If you find a suspicious rule, don't just delete it. Capture the full configuration (what it matches, where it sends mail, when it was created) because that's evidence of the attacker's target and timeline.
We enforce MFA. How are attackers getting past it?
Adversary-in-the-middle (AiTM) attacks intercept the session token, not the password. The attacker sits between your user and the real Microsoft 365 login page, captures the token that keeps someone signed in, and then uses that token directly. No password needed, no MFA prompt triggered.
AiTM accounted for 18.9% of identity-based threats in 2025. While the session stays valid, the attacker operates as the user. The countermeasures:
- Shorten session lifetime. Ask your identity team how long tokens stay active and whether a new device or location forces a fresh login.
- Require phishing-resistant MFA. NIST SP 800-63 defines phishing-resistant authenticators as those that resist real-time credential phishing. FIDO2 hardware tokens and passkeys meet this bar; SMS and app-based TOTP codes don't.
- Monitor for impossible-travel and new-device logins. If someone authenticated from Chicago at 2pm and Tokyo at 2:15pm, kill the session.
What's device code phishing and why does it survive password resets?
Device code phishing sends someone to Microsoft's real device code login (the flow designed for devices without browsers, like smart TVs). The victim enters a code, and the attacker holds an access token that can survive a password reset because it's tied to the device authorization, not the password.
Huntress saw a 1,380% increase comparing July-December 2025 to January-April 2026. The EvilTokens phishing kit hit 344 organizations across five countries in 16 days. The tactic is less frequent but highly damaging.
Your conditional access policy should require re-authentication when:
- A new device registers
- A user changes their password
- Risky sign-in behavior is detected
Review your Azure AD (now Entra ID) device code flow settings. Many organizations don't need device code authentication enabled at all. If you do, restrict it to specific user groups and log every device code request.
Are attackers really using AI for this stuff, or is that hype?
Both. Huntress marks six of the 11 tactics in their analysis for AI acceleration but files "AI platform abuse and deepfakes" under "overhyped, for now."
Confirmed: attackers use AI to write fake document-share and service-agreement lures. Jamie Levy, senior director of adversary tactics at Huntress, notes that attackers prefer pulling legitimate tools off the shelf over building from scratch, and AI speeds up the lure-writing part.
Real but contained: FakeAgent used a malicious Claude Artifact hosted on the real claude.ai domain to redirect people looking for Claude Desktop to SectopRAT, hitting 29 organizations in two days. That's platform abuse, not deepfakes or voice cloning.
The practical takeaway: train your team to verify requests through a second channel. If someone sends a document-share link or service agreement, call them or message them on a known-good number before clicking.
ClickFix keeps coming up in reports. What is it?
ClickFix is a social engineering tactic that uses fake CAPTCHA prompts or fake error messages to trick someone into running a command. The fake workflow might say "verify you're human by pressing Windows+R and pasting this command" or "fix this error by running this PowerShell script."
Huntress found ClickFix made up 53.2% of malware loader activity in 2025. It works because it looks like a legitimate troubleshooting step, and people are conditioned to follow on-screen instructions.
Block this at the policy level: disable PowerShell for standard users, require admin approval for script execution, and use application control policies (Windows Defender Application Control or AppLocker) to whitelist approved executables.
Where should we focus first?
If you can only tackle one thing this quarter, inventory your RMM tools and define what triggers an alert when a new one appears. That's the 45% problem. Then work backward through session lifetime, mailbox rule audits, and conditional access policies.
The Huntress data shows attackers gravitating toward legitimate tools because they blend in. Your monitoring needs to assume that approved software can be weaponized and that "it looked normal" isn't a defense anymore.





