Trusted Remote Tools Are Becoming Attack Vectors, HP Warns
Attackers are abusing legitimate remote access and blend as normal everyday IT activity.
As the workforce shifted to hybrid models after COVID, and as companies become more globalized, IT remote access and support software have become critical help desk tools.
However, those tools are increasingly used by bad actors to get inside organizations’ networks.
New research from HP shows that threat actors are tricking users into installing legitimate remote access software and then taking control of an endpoint.
Trusted Tools Are The New Backdoor
Attackers using legitimate software like LogMeIn and ScreenConnect to take control of devices increased in Q1 2026, according to HP’s new threat research report.
Moreover, “the [attack] campaigns relied on tax year-end phishing emails and fake desktop app downloads to install the tools without the user’s knowledge, giving attackers full control of victim devices while helping them avoid suspicion,” the report revealed.
Thirty-nine percent of these emails escaped security detection in Q1, the report states.
Threat actors can blend in with day-to-day IT activity by using digitally signed and trusted software. These hackers can get control of endpoints without setting off the usual security alerts.
The report gave further breakdowns of threats in Q1 2026:
- Executable files were the most ubiquitous malware delivers type, accounting for 39 percent of threats caught by HP Sure Click technology.
- Archive files like ZIP, RAR, GZ, 7Z and TAR were the top ruses used by threat actors.
- Malicious spreadsheets, PDFs and email are also top threat vectors.
Midmarket Is Particularly Exposed
With 72 percent of organizations operating in hybrid mode, 75 percent say hybrid work has amplified IT operational challenges.
Remote monitoring and management (RMM) is now core infrastructure, requiring IT teams to manage distributed endpoints often across the globe.
Attackers are prioritizing low effort techniques that can avoid detection.
Midmarket security teams can take several steps to help combat these kinds of attacks:
- Inventory remote access tools
- Audit access and control
- Monitor behaviors (are sessions occurring at unusual times or are software tools being installed outside normal working hours?)
- Rethink “trusted software” assumptions – just because its approved doesn’t mean its usage is safe.
Midmarket Takeaway
Risk with remote access tools isn’t new, but the way attackers are using is, HP’s report suggests. By using trusted IT support software, hackers are proving that you can’t assume legitimate tools are safe by default.