Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
The threats that most often knock companies off balance rarely match the flashy ones dominating cyber headlines. If you run a small or mid-sized organization, whether you handle IT yourself or outsource, you're working with limited time and tools while attackers keep moving faster than you can track. You need a clear picture of which attacks are really landing in environments like yours and which of those can quietly snowball, especially the ones that twist everyday tools into quiet business disruption.
That's why we created the Huntress Tragic Quadrant, a ranking of the most common threats we see putting your business at risk of a major unwanted interruption. Instead of focusing on what's trending in the news cycle, the Tragic Quadrant focuses on what our telemetry data and real-world Security Operations Center (SOC) investigations show us.
How the Tragic Quadrant works
The Tragic Quadrant ranks cyber tactics based on two factors:
How common a cyber tactic is across the environments we monitor (prevalence)
How close it puts an organization to major damage when it lands (pucker factor)
Figure 1: The Huntress Tragic Quadrant
The farther right a tactic lands, the more often we see it across our telemetry footprint. The higher it lands, the closer it sits to a business disruption event, especially without the right defenses to shut it down. That view comes from more than 5 million endpoints and 15 million identities spanning nearly 300,000 organizations we protect. The threats on this quadrant draw on data from detections and incidents we've worked on so far in 2026, the Huntress 2026 Cyber Threat Report, and in-the-wild examples our SOC has investigated across partner and customer environments. Wherever you see a solid dot, it means we've seen that threat accelerated by AI.
If you only have time to focus on one cyber threat, the top right is where to start. That OH $#!T corner is where tactics are both widespread and dangerously close to outcomes like ransomware, data theft, or business email compromise (BEC). That's where you can close the gap fastest before these tactics become major business disruptions.
Why the OH $#!T Corner deserves your immediate attention
The OH $#!T corner covers the techniques that show up most often and put you just a short step away from chaos when they get into your environment. These techniques intentionally lean on the types of tools and workflows your business already uses and trusts.
RMM abuse is steady and holding
Remote monitoring and management (RMM) tools are a staple for IT teams who need to manage systems from anywhere. That same access and persistence also make them attractive to attackers. Because RMM tools are already trusted, RMM abuse blends in with routine admin work. All it takes is one rogue RMM tool installed for an attacker to gain persistent access that looks just like ordinary administrator behavior.
In Q1 2026, 45% of endpoint-related incidents Huntress investigated involved RMM abuse. It's the single most common threat category we see on endpoints, and it's just one hop away from disasters like ransomware or data theft. We're already seeing attackers use AI to create convincing fake document shares and service agreement lures that trick users into downloading unwanted RMMs.
Mailbox manipulation as an entry point to business email compromise (BEC)
So far in 2026, 24.6% of Identity Threat Detection and Response (ITDR) signals point to mailbox manipulation and persistence. This is another sneaky tactic that gives attackers stealthy access to your existing tools without dropping malware. Once an attacker has access to a mailbox, they can quietly change inbox rules and route email traffic wherever they want. Think RSS Feeds or Archive folders that nobody is watching except for sneaky cybercriminals. This lets them shuffle replies from vendors into low-visibility folders, tweak invoice details, and ultimately run BEC scams, routing payments to their own accounts while draining your business accounts without raising an eyebrow.
Account takeover that sidesteps MFA
While there are different types of account takeover, the Tragic Quadrant focuses on adversary in the middle (AiTM) attacks, which were 18.9% of all identity-based threats Huntress tracked in 2025. Here, an attacker slips between a victim and a real Microsoft 365 login page, steals the session token in transit, and forwards everything on so nothing looks off to the user. As long as that session stays valid, the attacker can access the account without a password or a fresh MFA prompt.
Outside the OH $#!T corner
The Tragic Quadrant doesn't stop at the OH $#!T corner. Here are three examples from the other corners that still deserve a plan.
Device code phishing turns low-key deadly
Device code phishing is rated as low-key deadly because we don't see it as often, but it rides on Microsoft's real device code login flow, so most of the usual "check the URL" advice doesn't help. A convincing prompt nudges someone to enter a short code on a real Microsoft page. Once they do, the attacker ends up with an access token that can outlive a password reset and be reused quietly from somewhere else, without reprompting the user.
Figure 2: Attackers quietly hosted their token-harvesting infrastructure on Railway, a legitimate developer platform most security teams never flagged, and wrapped phishing links in legitimate Cisco, Trend Micro, and Mimecast redirect URLs so the emails sailed through filters untouched.
In one 16-day window, a single phishing-as-a-service (PhaaS) kit called EvilTokens hit 344 organizations across five countries using this exact pattern. It leaned on legitimate infrastructure and AI-tuned lures to move fast. Because these prompts run through Microsoft's own pages and familiar workflows, traditional checks like malware signatures don't buy you much. You need to watch for unusual device code prompts and odd token use, not just whether the page looks legitimate.
ClickFix is a daily pest with high stakes
ClickFix is a frequent intrusion pest, but it's usually a few steps away from a major incident. It abuses the copy-paste muscle memory people rely on to get through friction. A fake CAPTCHA or "verification failed" prompt walks someone through copying a command into their terminal. There's no exploit chain and no malware delivery. A single Control+V paste is the compromise that runs malicious code.
So far in 2026, ClickFix makes up about 2.2% of Managed Endpoint Detection and Response (EDR) detection signals, but nearly 99% of those detections are high severity. One malicious command pasted into a Run box is enough to open the door to infostealers, remote access tools, or ransomware.
Figure 3: A fake "Human Verification" prompted a victim to press Win+R, then paste one command into the Windows Run box. That launched a multi-stage infection ending in a LummaC2 infostealer compromise.
AI platform abuse is overhyped, for now
AI platform abuse maps to the overhyped, for now, corner because it's still an emerging pattern. Instead of sending people to random download sites, attackers hide malicious content behind real AI tools and workflows. A fake "desktop client" or "productivity helper" might live inside a shared conversation, a public mini app, or a hosted artifact on a trusted AI domain like Claude, ChatGPT, or Grok.
Figure 4: FakeAgent used a malicious Claude Artifact hosted on the real claude.ai domain to send people looking for Claude Desktop to SectopRAT, hitting 29 organizations in two days.
The real risk has shifted from how people might interact with "bad files" to how they behave inside tools they already trust, which links they follow, and when an "AI helper" suddenly turns into a download or install prompt that doesn't match normal work.
Where teams go from here
The Tragic Quadrant is designed to help you choose what to fix first when everything feels urgent. It gives you a starting point that meets your business where it's at.
If you're not sure where to begin, use the top right corner and ask simple questions. Which tools are approved? How do we monitor mailbox rules? How do we catch strange session behavior before it turns into something worse?
Download the Huntress Tragic Quadrant so you can work through every corner of the quadrant on your own timeline and prioritize which gaps to close next.
Join us on October 8 for a live hacking demo of the Tragic Quadrant cyber tactics. Huntress CEO Kyle Hanslovan will spin up real techniques from the Tragic Quadrant and show how fast they go from idea to impact in environments like yours. Save your spot now.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.