Every quarter, another vendor report lands with the same headline: phishing is still the top initial access vector. The instinct is to shrug. We’ve heard this for a decade, so why would this quarter be different? Here’s why it should worry you more, not less: Cisco Talos’ Q2 2026 incident response trends report doesn’t just show phishing winning again, it shows what happens after the click, and the second half of that story is the part most cybersecurity programs still aren’t built to handle. Attackers aren’t dropping custom malware anymore. They’re logging into remote management software your help desk already uses, and in at least one active botnet campaign, they’re exploiting a hardware feature that exists specifically to keep systems reliable. The tools built to keep your infrastructure running are being turned into the infrastructure of the attack.

The Phishing Numbers Are the Least Interesting Part of This Report
Yes, phishing climbed again as the leading cause of incidents Talos responded to this quarter. That’s not the finding worth sitting with. What matters is what attackers do once that phishing email lands a foothold: increasingly, they don’t reach for a payload at all. They reach for a remote monitoring and management tool, the same category of software your IT team already runs to patch laptops and troubleshoot printers remotely. Talos IR flagged a marked rise in RMM abuse this quarter as attackers pivoted from custom implants toward tools that are already on the allowlist, already trusted by endpoint detection, and already familiar to whoever’s watching the SIEM at 2 a.m.
This is the quiet failure mode of a lot of threat detection stacks: they’re tuned to catch what’s unusual, and a legitimate RMM agent phoning home is, by design, not unusual. An attacker who compromises credentials and pivots to a tool your organization already trusts doesn’t trip the alarms built for malware. They walk through the front door wearing a badge nobody thought to check twice.
Your RMM Allowlist Is an Attacker’s Roadmap
Once phishing gets an attacker a foothold, the fastest path to persistence and lateral movement is rarely a novel exploit. It’s whatever remote access software is already deployed across the environment. Talos IR’s data lines up with what incident responders have been saying informally for a couple of years now: attackers do reconnaissance on which RMM tools an organization runs before they ever try to install their own. If the target already has one deployed, that’s the one they’ll try to hijack, because uninstalling and reinstalling raises far more flags than reusing what’s already trusted.
This is a defense in depth problem more than a detection problem. If your RMM software has a single set of admin credentials shared across the helpdesk team, if there’s no multi-factor requirement on the management console, and if outbound connections from that tool aren’t logged with the same rigor as your VPN traffic, you’ve built a blind spot that scales with every endpoint the tool touches.
Killing the Process Doesn’t Always Kill the Botnet
If RMM abuse shows attackers exploiting trust in software, the Tengu botnet shows the same logic applied to hardware. Nozomi Networks Labs found Tengu, a Mirai-derived strain, spreading to Linux devices through brute-force attacks against exposed Telnet services, a reminder that credential stuffing and weak default logins are still doing heavy lifting for attackers in 2026. What makes Tengu worth a second look isn’t the delivery mechanism, though. It’s what happens when a defender successfully kills the malicious process.
The Watchdog Trick, Explained
Most embedded Linux devices, routers, IoT gear, industrial controllers, ship with a hardware watchdog timer. It’s a legitimate reliability feature: if the watchdog isn’t “petted” on a regular schedule, it assumes the system has hung and forces a reboot to restore service. Tengu abuses that exact mechanism. If a defender identifies and terminates its main process, the watchdog stops getting fed, the device reboots, and Tengu’s other persistence hooks get a fresh chance to relaunch before anyone’s back at the keyboard. The incident responder’s standard move, kill the malicious process, becomes the trigger for reinfection instead of the fix.
Once running, Tengu supports roughly two dozen distributed denial-of-service attack modes, giving whoever controls it a flexible platform rather than a single-purpose tool. But the persistence trick is the part that should change how defenders think about remediation on embedded and IoT devices generally: process termination alone is not incident response, it’s a pause button.
What Actually Works: Hardening the Trust You’ve Already Extended
None of this requires exotic new tooling. It requires treating the software and hardware features you already trust as part of your attack surface, not outside it. A few concrete moves:
- Inventory every RMM tool with access to your environment, including ones left behind by former MSPs or acquired business units. You can’t monitor what you’ve forgotten you’re running.
- Require phishing-resistant MFA on RMM management consoles, not just on email and VPN. This is frequently the softest credential in the environment.
- Log and alert on RMM tool behavior anomalies, unusual login times, new source IPs, or connections to endpoints the tool doesn’t normally manage, rather than trusting the tool category wholesale.
- Change default credentials and disable Telnet on every embedded and IoT device before it ships to production; brute-force attacks like the one seeding Tengu succeed almost entirely against defaults nobody rotated.
- For embedded devices with hardware watchdogs, plan remediation around full reimaging or firmware reset, not process termination, since a persistence mechanism that survives a reboot needs a fix that survives it too.
Firewall rules and brute-force lockouts still matter here, they’re what should have stopped Tengu’s Telnet scanning before it ever reached a honeypot, let alone a production device. But security hardening that stops at the network edge misses the second half of both these stories: the abuse that happens after a foothold is already established, using tools nobody flagged as risky.
The Access Management Market Is Catching Up, Slowly
It’s not a coincidence that identity and access governance is where the money is moving right now. Cyera’s reported $1 billion acquisition of Oasis Security, a company that raised $120 million just months ago for agentic access management, is a bet that the next wave of incidents won’t come from a novel exploit but from unmanaged access sprawl, human, machine, and increasingly AI agent identities that nobody fully inventoried. That’s the same root problem showing up in the Talos data: it’s not that attackers found a new door, it’s that too many trusted doors were left unmonitored.
Frequently Asked Questions
- Why is RMM tool abuse harder to detect than traditional malware?
- Because the software itself is legitimate and often already allowlisted by endpoint protection. Detection has to shift from “is this file malicious” to “is this trusted tool behaving abnormally,” which requires baseline behavior monitoring most teams haven’t built out.
- Does killing a malicious process ever make things worse?
- Yes, as Tengu demonstrates. If a botnet uses a hardware watchdog or another reboot-triggering persistence hook, killing the process without addressing the underlying persistence mechanism can trigger a reboot that simply relaunches the threat.
- What’s the fastest way to reduce exposure to both trends at once?
- Audit every RMM tool with production access and enforce MFA on its console, and separately, rotate default credentials and disable unnecessary remote access protocols like Telnet on any embedded or IoT device before deployment.
Sources
- IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
- Cyera Acquiring Oasis Security in $1 Billion Deal
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
