Huntress has published its first SMB Threat Report, analyzing Q3 2023 data from 2.4 million endpoints and over 1 million Microsoft 365 user entities. Key findings include: 56% of incidents were malware-free, with attackers favoring living-off-the-land tactics like LOLBins (29%) and scripting framework abuse (27%); RMM tools were hijacked in 65% of incidents for persistence or remote access; 64% of Microsoft 365 incidents involved malicious inbox rules tied to business email compromise; and ransomware targeting SMBs is diversifying, with 60% of observed strains being unknown or uncategorized, while LockBit accounted for 25%.