Living off the land attacks now drive 84% of severe breaches

A modern data centre corridor with rows of illuminated server racks on both sides, a reflective floor, and a closed white door at the end—an environment where robust cyber security helps guard against severe breaches.

Bitdefender’s newly released 2026 Cybersecurity Assessment has confirmed something the industry has suspected for a while: the biggest active threat to most businesses is not exotic new malware. It is attackers quietly using the tools already installed on your network.

The report, based on an independent survey of 1,200 IT and cybersecurity professionals across six countries, found that 84% of high-severity attacks analysed by Bitdefender Labs used Living off the Land (LOTL) techniques. Yet only one in five of the professionals surveyed ranked LOTL attacks among their top three concerns. That gap between what is actually happening and what security teams are watching for is the real story here.

What a living off the land attack actually looks like

LOTL attacks abuse legitimate software and system utilities that are already present in an environment, rather than introducing new malicious files. Tools such as PowerShell, Windows Management Instrumentation, and remote desktop protocol get repurposed by attackers to move through a network undetected.

The reason this technique is so effective is straightforward. Traditional antivirus and signature-based detection is built to spot unfamiliar files and known malware patterns. A LOTL attack does not look unfamiliar. It looks like normal admin activity, because in most cases it is using the same tools your own IT team relies on every day.

For Mac-first and hybrid businesses, this matters just as much as it does in Windows-heavy environments. macOS has its own set of built-in scripting and remote management tools that can be misused in the same way if endpoint monitoring is not configured to flag unusual behaviour rather than just unusual files.

Why AI is getting the attention, and LOTL is not

The Bitdefender survey found that security professionals rank AI-related threats, including self-mutating malware, public LLM data leakage, and AI-driven evasion, as their top concerns. That instinct is not wrong. AI is changing how attacks are built and delivered.

But the report is clear that AI is mostly being used to make existing attack techniques faster and more convincing, rather than to invent entirely new categories of threat. Meanwhile, LOTL techniques, which do not need any AI at all, are already responsible for the overwhelming majority of severe attacks. The attention is on tomorrow’s threat while today’s most common one goes comparatively unwatched.

Dr Logic’s perspective

In Dr Logic’s experience, the businesses most exposed to LOTL-style attacks are not the ones without security tools. They are the ones whose device management and monitoring only flags known bad files, rather than unusual patterns of legitimate tool use. A properly configured DMS (formerly MDM) platform, paired with endpoint monitoring that tracks behaviour rather than just file signatures, closes a large part of this gap.

We recommend treating built-in admin and scripting tools as a monitored asset class in their own right, not an afterthought behind antivirus and firewall spend. If nobody is watching how those tools are being used, an attacker does not need to bring anything new into your environment at all.

What this means for your business

Reducing LOTL exposure does not require ripping out existing tools. It requires visibility into how they are being used, and a plan for restricting or alerting on unusual activity. That is a configuration and monitoring conversation, not a new product purchase.

If your current setup would not flag someone unusually using a legitimate admin tool, that is worth raising with your IT provider this quarter, not after an incident forces the question.

Talk to Dr Logic about strengthening your endpoint monitoring and attack surface visibility.

Related articles

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.