<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk" -->

---
title: Huntress Tragic Quadrant: Top Cyber Threats Wrecking...
description: Huntress published its 'Tragic Quadrant,' a ranking of cyber threats hitting small and mid-sized businesses most often, based on telemetry from over 5 million...
canonical: https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses | daily.dev
og:description: Huntress published its 'Tragic Quadrant,' a ranking of cyber threats hitting small and mid-sized businesses most often, based on telemetry from over 5 million...
og:url: https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk
og:image: https://api.daily.dev/og/posts/d6KhZhavk.png
og:image:alt: Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 8 min read · 0 upvotes · 0 comments

## Summary

Huntress published its 'Tragic Quadrant,' a ranking of cyber threats hitting small and mid-sized businesses most often, based on telemetry from over 5 million endpoints and 300,000 organizations. The top 'OH $#!T' corner includes RMM abuse (45% of Q1 2026 endpoint incidents), mailbox manipulation enabling BEC (24.6% of ITDR signals), and AiTM attacks that steal session tokens to bypass MFA (18.9% of identity threats in 2025). Other notable threats include device code phishing (a PhaaS kit called EvilTokens hit 344 organizations in 16 days), ClickFix clipboard-hijacking scams (2.2% of EDR signals but nearly 99% high severity), and emerging AI platform abuse where malicious content hides behind trusted AI tools like Claude or ChatGPT.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/huntress-tragic-quadrant-cyber-threats>

## Questions this post answers

### What percentage of endpoint incidents involve RMM tool abuse?

RMM abuse accounted for 45% of endpoint-related incidents investigated in Q1 2026, making it the single most common threat category observed on endpoints. Attackers install a rogue remote monitoring and management tool to gain persistent access that blends in with normal administrator activity, often just one step away from ransomware or data theft.

_Teams prioritizing which security gaps to close first can track threat trends like this on daily.dev._

### How common are adversary-in-the-middle (AiTM) attacks that bypass MFA?

AiTM attacks made up 18.9% of all identity-based threats tracked in 2025. In these attacks, an adversary intercepts the session between a victim and a real Microsoft 365 login page, steals the session token, and forwards traffic so nothing appears abnormal, allowing account access without needing a password or fresh MFA prompt.

_Developers building auth flows that depend on session tokens can follow threats like AiTM on daily.dev._

### How severe are ClickFix attacks that trick users into pasting commands into the Windows Run box?

ClickFix detections make up about 2.2% of managed EDR detection signals, but nearly 99% of those detections are rated high severity. A fake CAPTCHA or verification prompt tricks a user into pasting one malicious command into the Run dialog, which can lead to infostealers, remote access tools, or ransomware without any exploit chain or malware download.

_Anyone hardening endpoint defenses against social-engineering tactics like ClickFix can follow updates on daily.dev._

## Similar posts on daily.dev

- [Cybercrime Goes Corporate: Huntress Report Reveals Rise of Scalable, Stealth-First Attacks](https://daily.dev/posts/cybercrime-goes-corporate-huntress-report-reveals-rise-of-scalable-stealth-first-attacks-6forbf2ua) · IT Security Guru · 0 upvotes · 0 comments
- [5 Modern Threats You Need to Watch](https://daily.dev/posts/5-modern-threats-you-need-to-watch-ic96ecj6o) · Huntress Blog · 0 upvotes · 0 comments
- [4th May – Threat Intelligence Report](https://daily.dev/posts/4th-may-threat-intelligence-report-o8uni6wf4) · Check Point Research · 0 upvotes · 0 comments
- [Top techniques attackers use to infiltrate your systems today](https://daily.dev/posts/top-techniques-attackers-use-to-infiltrate-your-systems-today-38bwedayy) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses","url":"https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk"},"datePublished":"2026-10-01T13:46:06.969Z","dateModified":"2026-10-01T15:09:53.585Z","description":"Huntress published its 'Tragic Quadrant,' a ranking of cyber threats hitting small and mid-sized businesses most often, based on telemetry from over 5 million...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8e0f8c6901725209651c69f8a51ebcf4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8e0f8c6901725209651c69f8a51ebcf4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Huntress Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Huntress Blog","logo":"https://media.daily.dev/image/upload/s--kDC1MDsj--/f_auto,q_auto/v1780213277/logos/huntress-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/huntress-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ransomware,phishing","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Huntress Blog","item":"https://daily.dev/sources/huntress-blog"},{"@type":"ListItem","position":3,"name":"Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/huntress-tragic-quadrant-top-cyber-threats-wrecking-businesses-d6khzhavk#faq","mainEntity":[{"@type":"Question","name":"What percentage of endpoint incidents involve RMM tool abuse?","acceptedAnswer":{"@type":"Answer","text":"RMM abuse accounted for 45% of endpoint-related incidents investigated in Q1 2026, making it the single most common threat category observed on endpoints. Attackers install a rogue remote monitoring and management tool to gain persistent access that blends in with normal administrator activity, often just one step away from ransomware or data theft. Teams prioritizing which security gaps to close first can track threat trends like this on daily.dev."}},{"@type":"Question","name":"How common are adversary-in-the-middle (AiTM) attacks that bypass MFA?","acceptedAnswer":{"@type":"Answer","text":"AiTM attacks made up 18.9% of all identity-based threats tracked in 2025. In these attacks, an adversary intercepts the session between a victim and a real Microsoft 365 login page, steals the session token, and forwards traffic so nothing appears abnormal, allowing account access without needing a password or fresh MFA prompt. Developers building auth flows that depend on session tokens can follow threats like AiTM on daily.dev."}},{"@type":"Question","name":"How severe are ClickFix attacks that trick users into pasting commands into the Windows Run box?","acceptedAnswer":{"@type":"Answer","text":"ClickFix detections make up about 2.2% of managed EDR detection signals, but nearly 99% of those detections are rated high severity. A fake CAPTCHA or verification prompt tricks a user into pasting one malicious command into the Run dialog, which can lead to infostealers, remote access tools, or ransomware without any exploit chain or malware download. Anyone hardening endpoint defenses against social-engineering tactics like ClickFix can follow updates on daily.dev."}}]}
```

